Kaspersky Lab's Global Research and Analysis Team. (2014, August 7). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroburos. Retrieved December 11, 2014.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareEpic | Epic uses the |
| T1007 System Service Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running services and associated processes using the |
| T1012 Query Registry |
MalwareEpic | Epic uses the |
| T1012 Query Registry |
GroupTurla | Turla surveys a system upon check-in to discover information in the Windows Registry with the |
| T1014 Rootkit |
MalwareUroburos | Uroburos can use its kernel module to prevent its host components from being listed by the targeted system's OS and to mediate requests between user mode and concealed components. |
| T1016 System Network Configuration Discovery |
MalwareEpic | Epic uses the |
| T1016 System Network Configuration Discovery |
GroupTurla | Turla surveys a system upon check-in to discover network configuration details using the |
| T1018 Remote System Discovery |
GroupTurla | Turla surveys a system upon check-in to discover remote systems on a local network using the |
| T1018 Remote System Discovery |
MalwareEpic | Epic uses the |
| T1021.002 SMB/Windows Admin Shares |
GroupTurla | Turla used |
| T1027 Obfuscated Files or Information |
MalwareEpic | Epic heavily obfuscates its code to make analysis more difficult. |
| T1049 System Network Connections Discovery |
MalwareEpic | Epic uses the |
| T1049 System Network Connections Discovery |
GroupTurla | Turla surveys a system upon check-in to discover active local network connections using the |
| T1057 Process Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running processes using the |
| T1057 Process Discovery |
MalwareEpic | Epic uses the |
| T1071.001 Web Protocols |
MalwareEpic | Epic uses HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
GroupTurla | Turla surveys a system upon check-in to discover operating system configuration details using the |
| T1083 File and Directory Discovery |
GroupTurla | Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the |
| T1083 File and Directory Discovery |
MalwareEpic | Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories. |
| T1110 Brute Force |
GroupTurla | Turla may attempt to connect to systems within a victim's network using |
| T1124 System Time Discovery |
GroupTurla | Turla surveys a system upon check-in to discover the system time by using the |
| T1124 System Time Discovery |
MalwareEpic | Epic uses the |
| T1518.001 Security Software Discovery |
MalwareEpic | Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them. |
| T1553.002 Code Signing |
MalwareEpic | Turla has used valid digital certificates from Sysprint AG to sign its Epic dropper. |
| T1560 Archive Collected Data |
MalwareEpic | Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server. |
| T1573.001 Symmetric Cryptography |
MalwareEpic | Epic encrypts commands from the C2 server using a hardcoded key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.