ATT&CKReferencesBromium Ursnif Mar 2017

Bromium Ursnif Mar 2017

Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareUrsnif

Ursnif droppers execute base64 encoded PowerShell commands.

T1027.013
Encrypted/Encoded File
MalwareUrsnif

Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.

T1047
Windows Management Instrumentation
MalwareUrsnif

Ursnif droppers have used WMI classes to execute PowerShell commands.

T1059.001
PowerShell
MalwareUrsnif

Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload.

T1059.005
Visual Basic
MalwareUrsnif

Ursnif droppers have used VBA macros to download and execute the malware's full executable payload.

T1559.001
Component Object Model
MalwareUrsnif

Ursnif droppers have used COM objects to execute the malware's full executable payload.

T1564.003
Hidden Window
MalwareUrsnif

Ursnif droppers have used COM properties to execute malware in hidden windows.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.