ATT&CKReferencesNorthSec 2015 GData Uroburos Tools

NorthSec 2015 GData Uroburos Tools

Rascagneres, P. (2015, May). Tools used by the Uroburos actors. Retrieved August 18, 2016.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1071.001
Web Protocols
MalwareComRAT

ComRAT has used HTTP requests for command and control.

T1546.015
Component Object Model Hijacking
MalwareComRAT

ComRAT samples have been seen which hijack COM objects for persistence by replacing the path to shell32.dll in registry location HKCU\Software\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.