Microsoft. (2017, November 9). Backdoor:Win32/Wingbird.A!dha. Retrieved November 27, 2017.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1543.003 Windows Service |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1547.008 LSASS Driver |
MalwareWingbird | Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes. |
| T1569.002 Service Execution |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1574.001 DLL |
MalwareWingbird | Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.