Falcone, R. and Lee, B. (2017, October 9). OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan. Retrieved January 8, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareISMInjector | ISMInjector is obfuscated with the off-the-shelf SmartAssembly .NET obfuscator created by red-gate.com. |
| T1053.005 Scheduled Task |
MalwareISMInjector | ISMInjector creates scheduled tasks to establish persistence. |
| T1055.012 Process Hollowing |
MalwareISMInjector | ISMInjector hollows out a newly created process RegASM.exe and injects its payload into the hollowed process. |
| T1059.001 PowerShell |
GroupOilRig | OilRig has used PowerShell scripts for execution, including use of a macro to run a PowerShell command to decode file contents. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareISMInjector | ISMInjector uses the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.