ATT&CKReferencesProofPoint Ursnif Aug 2016

ProofPoint Ursnif Aug 2016

Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareUrsnif

Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.

T1041
Exfiltration Over C2 Channel
MalwareUrsnif

Ursnif has used HTTP POSTs to exfil gathered information.

T1071.001
Web Protocols
MalwareUrsnif

Ursnif has used HTTPS for C2.

T1090
Proxy
MalwareUrsnif

Ursnif has used a peer-to-peer (P2P) network for C2.

T1090.003
Multi-hop Proxy
MalwareUrsnif

Ursnif has used Tor for C2.

T1112
Modify Registry
MalwareUrsnif

Ursnif has used Registry modifications as part of its installation routine.

T1132
Data Encoding
MalwareUrsnif

Ursnif has used encoded data in HTTP URLs for C2.

T1140
Deobfuscate/Decode Files or Information
MalwareUrsnif

Ursnif has used crypto key information stored in the Registry to decrypt Tor clients dropped to disk.

T1568.002
Domain Generation Algorithms
MalwareUrsnif

Ursnif has used a DGA to generate domain names for C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.