ATT&CKReferencesFireEye Ursnif Nov 2017

FireEye Ursnif Nov 2017

Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
MalwareUrsnif

Ursnif has used HTTP POSTs to exfil gathered information.

T1055.005
Thread Local Storage
MalwareUrsnif

Ursnif has injected code into target processes via thread local storage callbacks.

T1055.012
Process Hollowing
MalwareUrsnif

Ursnif has used process hollowing to inject into child processes.

T1071.001
Web Protocols
MalwareUrsnif

Ursnif has used HTTPS for C2.

T1106
Native API
MalwareUrsnif

Ursnif has used CreateProcessW to create child processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.