Pedro Tavares (Segurança Informática). (2020, September 15). Threat analysis: The emergent URSA trojan impacts many countries using a sophisticated loader. Retrieved March 13, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
MalwareMispadu | Mispadu's binary is injected into memory via `WriteProcessMemory`. |
| T1056.002 GUI Input Capture |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1106 Native API |
MalwareMispadu | Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory. |
| T1217 Browser Information Discovery |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1555 Credentials from Password Stores |
MalwareMispadu | Mispadu has obtained credentials from mail clients via NirSoft MailPassView. |
| T1573.002 Asymmetric Cryptography |
MalwareMispadu | Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic. |
| T1614.001 System Language Discovery |
MalwareMispadu | Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.