Kaspersky Lab's Global Research & Analysis Team. (2014, August 06). The Epic Turla Operation: Solving some of the mysteries of Snake/Uroboros. Retrieved November 7, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareEpic | Epic collects the user name from the victim’s machine. |
| T1049 System Network Connections Discovery |
MalwareEpic | Epic uses the |
| T1057 Process Discovery |
MalwareEpic | Epic uses the |
| T1069.001 Local Groups |
MalwareEpic | Epic gathers information on local group names. |
| T1070.004 File Deletion |
MalwareEpic | Epic has a command to delete a file from the machine. |
| T1071.001 Web Protocols |
MalwareEpic | Epic uses HTTP and HTTPS for C2 communications. |
| T1082 System Information Discovery |
MalwareEpic | Epic collects the OS version, hardware information, computer name, available system memory status, and system and user language settings. |
| T1083 File and Directory Discovery |
MalwareEpic | Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories. |
| T1087.001 Local Account |
MalwareEpic | Epic gathers a list of all user accounts, privilege classes, and time of last logon. |
| T1560 Archive Collected Data |
MalwareEpic | Epic encrypts collected data using a public key framework before sending it over the C2 channel. Some variants encrypt the collected data with AES and encode it with base64 before transmitting it to the C2 server. |
| T1560.002 Archive via Library |
MalwareEpic | Epic compresses the collected data with bzip2 before sending it to the C2 server. |
| T1680 Local Storage Discovery |
MalwareEpic | Epic collects disk space information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.