ATT&CKReferencesTrendMicro PE_URSNIF.A2

TrendMicro PE_URSNIF.A2

Trend Micro. (2014, December 11). PE_URSNIF.A2. Retrieved June 5, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1055.005
Thread Local Storage
MalwareUrsnif

Ursnif has injected code into target processes via thread local storage callbacks.

T1105
Ingress Tool Transfer
MalwareUrsnif

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.

T1543.003
Windows Service
MalwareUrsnif

Ursnif has registered itself as a system service in the Registry for automatic execution at system startup.

T1547.001
Registry Run Keys / Startup Folder
MalwareUrsnif

Ursnif has used Registry Run keys to establish automatic execution at system startup.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.