ATT&CKReferencesOilRig New Delivery Oct 2017

OilRig New Delivery Oct 2017

Falcone, R. and Lee, B. (2017, October 9). OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan. Retrieved January 8, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareISMInjector

ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com.

T1053.005
Scheduled Task
MalwareISMInjector

ISMInjector creates scheduled tasks to establish persistence.

T1055.012
Process Hollowing
MalwareISMInjector

ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process.

T1059.001
PowerShell
GroupOilRig

OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents.

T1140
Deobfuscate/Decode Files or Information
GroupOilRig

A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims.

T1140
Deobfuscate/Decode Files or Information
MalwareISMInjector

ISMInjector uses the certutil command to decode a payload file.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.