Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareOopsIE | OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings. |
| T1027.002 Software Packing |
MalwareOopsIE | OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2. |
| T1030 Data Transfer Size Limits |
MalwareOopsIE | OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks. |
| T1041 Exfiltration Over C2 Channel |
MalwareOopsIE | OopsIE can upload files from the victim's machine to its C2 server. |
| T1053.005 Scheduled Task |
MalwareOopsIE | OopsIE creates a scheduled task to run itself every three minutes. |
| T1053.005 Scheduled Task |
GroupOilRig | OilRig has created scheduled tasks that run a VBScript to execute a payload on victim machines. |
| T1059 Command and Scripting Interpreter |
GroupOilRig | OilRig has used various types of scripting for execution. |
| T1059.003 Windows Command Shell |
GroupOilRig | OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts. |
| T1059.003 Windows Command Shell |
MalwareOopsIE | OopsIE uses the command prompt to execute commands on the victim's machine. |
| T1059.005 Visual Basic |
MalwareOopsIE | OopsIE creates and uses a VBScript as part of its persistent execution. |
| T1070.004 File Deletion |
GroupOilRig | OilRig has deleted files associated with their payload after execution. |
| T1071.001 Web Protocols |
MalwareOopsIE | OopsIE uses HTTP for C2 communications. |
| T1074.001 Local Data Staging |
MalwareOopsIE | OopsIE stages the output from command execution and collected files in specific folders before exfiltration. |
| T1105 Ingress Tool Transfer |
MalwareOopsIE | OopsIE can download files from its C2 server to the victim's machine. |
| T1132.001 Standard Encoding |
MalwareOopsIE | OopsIE encodes data in hexadecimal format over the C2 channel. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareOopsIE | OopsIE concatenates then decompresses multiple resources to load an embedded .Net Framework assembly. |
| T1140 Deobfuscate/Decode Files or Information |
GroupOilRig | A OilRig macro has run a PowerShell command to decode file contents. OilRig has also used certutil to decode base64-encoded files on victims. |
| T1204.001 Malicious Link |
GroupOilRig | OilRig has delivered malicious links to achieve execution on the target system. |
| T1204.002 Malicious File |
GroupOilRig | OilRig has delivered macro-enabled documents that required targets to click the "enable content" button to execute the payload on the system. |
| T1560.001 Archive via Utility |
MalwareOopsIE | OopsIE compresses collected files with GZipStream before sending them to its C2 server. |
| T1560.003 Archive via Custom Method |
MalwareOopsIE | OopsIE compresses collected files with a simple character replacement scheme before sending them to its C2 server. |
| T1566.001 Spearphishing Attachment |
GroupOilRig | OilRig has sent spearphising emails with malicious attachments to potential victims using compromised and/or spoofed email accounts. |
| T1566.002 Spearphishing Link |
GroupOilRig | OilRig has sent spearphising emails with malicious links to potential victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.