Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareWingbird | Wingbird performs multiple process injections to hijack system processes and execute malicious code. |
| T1068 Exploitation for Privilege Escalation |
MalwareWingbird | Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges. |
| T1070.004 File Deletion |
MalwareWingbird | Wingbird deletes its payload along with the payload's parent process after it finishes copying files. |
| T1082 System Information Discovery |
MalwareWingbird | Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit. |
| T1518.001 Security Software Discovery |
MalwareWingbird | Wingbird checks for the presence of Bitdefender security software. |
| T1543.003 Windows Service |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1547.008 LSASS Driver |
MalwareWingbird | Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes. |
| T1569.002 Service Execution |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1574.001 DLL |
MalwareWingbird | Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.