ATT&CKReferencesSegurança Informática URSA Sophisticated Loader 2020

Segurança Informática URSA Sophisticated Loader 2020

Pedro Tavares (Segurança Informática). (2020, September 15). Threat analysis: The emergent URSA trojan impacts many countries using a sophisticated loader. Retrieved March 13, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareMispadu

Mispadu's binary is injected into memory via `WriteProcessMemory`.

T1056.002
GUI Input Capture
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1106
Native API
MalwareMispadu

Mispadu has used a variety of Windows API calls, including ShellExecute and WriteProcessMemory.

T1217
Browser Information Discovery
MalwareMispadu

Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1555
Credentials from Password Stores
MalwareMispadu

Mispadu has obtained credentials from mail clients via NirSoft MailPassView.

T1573.002
Asymmetric Cryptography
MalwareMispadu

Mispadu contains a copy of the OpenSSL library to encrypt C2 traffic.

T1614.001
System Language Discovery
MalwareMispadu

Mispadu checks and will terminate execution if the compromised system’s language ID is not Spanish or Portuguese.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.