ATT&CKReferencesUnit 42 OopsIE! Feb 2018

Unit 42 OopsIE! Feb 2018

Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareOopsIE

OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings.

T1027.002
Software Packing
MalwareOopsIE

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.

T1030
Data Transfer Size Limits
MalwareOopsIE

OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks.

T1041
Exfiltration Over C2 Channel
MalwareOopsIE

OopsIE can upload files from the victim's machine to its C2 server.

T1053.005
Scheduled Task
MalwareOopsIE

OopsIE creates a scheduled task to run itself every three minutes.

T1053.005
Scheduled Task
GroupOilRig

OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059.003
Windows Command Shell
GroupOilRig

OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.

T1059.003
Windows Command Shell
MalwareOopsIE

OopsIE uses the command prompt to execute commands on the victim's machine.

T1059.005
Visual Basic
MalwareOopsIE

OopsIE creates and uses a VBScript as part of its persistent execution.

T1070.004
File Deletion
GroupOilRig

OilRig has deleted files associated with their payload after execution.

T1071.001
Web Protocols
MalwareOopsIE

OopsIE uses HTTP for C2 communications.

T1074.001
Local Data Staging
MalwareOopsIE

OopsIE stages the output from command execution and collected files in specific folders before exfiltration.

T1105
Ingress Tool Transfer
MalwareOopsIE

OopsIE can download files from its C2 server to the victim's machine.

T1132.001
Standard Encoding
MalwareOopsIE

OopsIE encodes data in hexadecimal format over the C2 channel.

T1140
Deobfuscate/Decode Files or Information
MalwareOopsIE

OopsIE concatenates then decompresses multiple resources to load an embedded .Net Framework assembly.

T1140
Deobfuscate/Decode Files or Information
GroupOilRig

A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims.

T1204.001
Malicious Link
GroupOilRig

OilRig has delivered malicious links to achieve execution on the target system.

T1204.002
Malicious File
GroupOilRig

OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system.

T1560.001
Archive via Utility
MalwareOopsIE

OopsIE compresses collected files with GZipStream before sending them to its C2 server.

T1560.003
Archive via Custom Method
MalwareOopsIE

OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server.

T1566.001
Spearphishing Attachment
GroupOilRig

OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts.

T1566.002
Spearphishing Link
GroupOilRig

OilRig has sent spearphising emails with malicious links to potential victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.