Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1055 Process Injection |
Wingbird performs multiple process injections to hijack system processes and execute malicious code. |
| T1068 Exploitation for Privilege Escalation |
Wingbird exploits CVE-2016-4117 to allow an executable to gain escalated privileges. |
| T1070.004 File Deletion |
Wingbird deletes its payload along with the payload's parent process after it finishes copying files. |
| T1082 System Information Discovery |
Wingbird checks the victim OS version after executing to determine where to drop files based on whether the victim is 32-bit or 64-bit. |
| T1518.001 Security Software Discovery |
Wingbird checks for the presence of Bitdefender security software. |
| T1543.003 Windows Service |
Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1547.008 LSASS Driver |
Wingbird drops a malicious file (sspisrv.dll) alongside a copy of lsass.exe, which is used to register a service that loads sspisrv.dll as a driver. The payload of the malicious driver (located in its entry-point function) is executed when loaded by lsass.exe before the spoofed service becomes unstable and crashes. |
| T1569.002 Service Execution |
Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1574.001 DLL |
Wingbird side loads a malicious file, sspisrv.dll, in part of a spoofed lssas.exe service. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.