ATT&CKReferencesUnit42 OilRig Nov 2018

Unit42 OilRig Nov 2018

Falcone, R., Wilhoit, K.. (2018, November 16). Analyzing OilRig’s Ops Tempo from Testing to Weaponization to Delivery. Retrieved April 23, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1027.005
Indicator Removal from Tools
GroupOilRig

OilRig has tested malware samples to determine AV detection and subsequently modified the samples to ensure AV evasion.

T1027.013
Encrypted/Encoded File
GroupOilRig

OilRig has encrypted and encoded data in its malware, including by using base64.

T1059
Command and Scripting Interpreter
GroupOilRig

OilRig has used various types of scripting for execution.

T1059.003
Windows Command Shell
GroupOilRig

OilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.