Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareUrsnif | Ursnif has gathered information about running services. |
| T1012 Query Registry |
MalwareUrsnif | Ursnif has used Reg to query the Registry for installed programs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareUrsnif | Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names. |
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1055.005 Thread Local Storage |
MalwareUrsnif | Ursnif has injected code into target processes via thread local storage callbacks. |
| T1056.004 Credential API Hooking |
MalwareUrsnif | Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers. |
| T1057 Process Discovery |
MalwareUrsnif | Ursnif has gathered information about running processes. |
| T1070.004 File Deletion |
MalwareUrsnif | Ursnif has deleted data staged in tmp files after exfiltration. |
| T1071.001 Web Protocols |
MalwareUrsnif | Ursnif has used HTTPS for C2. |
| T1074.001 Local Data Staging |
MalwareUrsnif | Ursnif has used tmp files to stage gathered information. |
| T1080 Taint Shared Content |
MalwareUrsnif | Ursnif has copied itself to and infected files in network drives for propagation. |
| T1082 System Information Discovery |
MalwareUrsnif | Ursnif has used Systeminfo to gather system information. |
| T1091 Replication Through Removable Media |
MalwareUrsnif | Ursnif has copied itself to and infected removable drives for propagation. |
| T1113 Screen Capture |
MalwareUrsnif | Ursnif has used hooked APIs to take screenshots. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.