Vaish, A. & Nemes, S. (2017, November 28). Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection. Retrieved June 5, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1041 Exfiltration Over C2 Channel |
MalwareUrsnif | Ursnif has used HTTP POSTs to exfil gathered information. |
| T1055.005 Thread Local Storage |
MalwareUrsnif | Ursnif has injected code into target processes via thread local storage callbacks. |
| T1055.012 Process Hollowing |
MalwareUrsnif | Ursnif has used process hollowing to inject into child processes. |
| T1071.001 Web Protocols |
MalwareUrsnif | Ursnif has used HTTPS for C2. |
| T1106 Native API |
MalwareUrsnif | Ursnif has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.