Falcone, R., et al. (2018, September 04). OilRig Targets a Middle Eastern Government and Adds Evasion Techniques to OopsIE. Retrieved September 24, 2018.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareOopsIE | OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings. |
| T1047 Windows Management Instrumentation |
MalwareOopsIE | OopsIE uses WMI to perform discovery techniques. |
| T1053.005 Scheduled Task |
MalwareOopsIE | OopsIE creates a scheduled task to run itself every three minutes. |
| T1059.003 Windows Command Shell |
MalwareOopsIE | OopsIE uses the command prompt to execute commands on the victim's machine. |
| T1059.005 Visual Basic |
MalwareOopsIE | OopsIE creates and uses a VBScript as part of its persistent execution. |
| T1070.004 File Deletion |
MalwareOopsIE | OopsIE has the capability to delete files and scripts from the victim's machine. |
| T1071.001 Web Protocols |
MalwareOopsIE | OopsIE uses HTTP for C2 communications. |
| T1082 System Information Discovery |
MalwareOopsIE | OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks. |
| T1105 Ingress Tool Transfer |
MalwareOopsIE | OopsIE can download files from its C2 server to the victim's machine. |
| T1124 System Time Discovery |
MalwareOopsIE | OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone. |
| T1497.001 System Checks |
MalwareOopsIE | OopsIE performs several anti-VM and sandbox checks on the victim's machine. One technique the group has used was to perform a WMI query |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.