ATT&CKReferencesUnit 42 OilRig Sept 2018

Unit 42 OilRig Sept 2018

Falcone, R., et al. (2018, September 04). OilRig Targets a Middle Eastern Government and Adds Evasion Techniques to OopsIE. Retrieved September 24, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareOopsIE

OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings.

T1047
Windows Management Instrumentation
MalwareOopsIE

OopsIE uses WMI to perform discovery techniques.

T1053.005
Scheduled Task
MalwareOopsIE

OopsIE creates a scheduled task to run itself every three minutes.

T1059.003
Windows Command Shell
MalwareOopsIE

OopsIE uses the command prompt to execute commands on the victim's machine.

T1059.005
Visual Basic
MalwareOopsIE

OopsIE creates and uses a VBScript as part of its persistent execution.

T1070.004
File Deletion
MalwareOopsIE

OopsIE has the capability to delete files and scripts from the victim's machine.

T1071.001
Web Protocols
MalwareOopsIE

OopsIE uses HTTP for C2 communications.

T1082
System Information Discovery
MalwareOopsIE

OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks.

T1105
Ingress Tool Transfer
MalwareOopsIE

OopsIE can download files from its C2 server to the victim's machine.

T1124
System Time Discovery
MalwareOopsIE

OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone.

T1497.001
System Checks
MalwareOopsIE

OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query SELECT * FROM MSAcpi_ThermalZoneTemperature to check the temperature to see if it’s running in a virtual environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.