Holland, A. (2019, March 7). Tricks and COMfoolery: How Ursnif Evades Detection. Retrieved June 10, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareUrsnif | Ursnif droppers execute base64 encoded PowerShell commands. |
| T1027.013 Encrypted/Encoded File |
MalwareUrsnif | Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands. |
| T1047 Windows Management Instrumentation |
MalwareUrsnif | Ursnif droppers have used WMI classes to execute PowerShell commands. |
| T1059.001 PowerShell |
MalwareUrsnif | Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload. |
| T1059.005 Visual Basic |
MalwareUrsnif | Ursnif droppers have used VBA macros to download and execute the malware's full executable payload. |
| T1559.001 Component Object Model |
MalwareUrsnif | Ursnif droppers have used COM objects to execute the malware's full executable payload. |
| T1564.003 Hidden Window |
MalwareUrsnif | Ursnif droppers have used COM properties to execute malware in hidden windows. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.