Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareUrsnif | Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands. |
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1071.001 Web Protocols |
MalwareUrsnif | Ursnif has used HTTPS for C2. |
| T1090 Proxy |
MalwareUrsnif | Ursnif has used a peer-to-peer (P2P) network for C2. |
| T1090.003 Multi-hop Proxy |
MalwareUrsnif | |
| T1112 Modify Registry |
MalwareUrsnif | Ursnif has used Registry modifications as part of its installation routine. |
| T1132 Data Encoding |
MalwareUrsnif | Ursnif has used encoded data in HTTP URLs for C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareUrsnif | Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk. |
| T1568.002 Domain Generation Algorithms |
MalwareUrsnif | Ursnif has used a DGA to generate domain names for C2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.