Ursnif

S0386

Malware.View on attack.mitre.org

About this malware

Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links. Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1005
Data from Local System

Ursnif has collected files from victim machines, including certificates and cookies.

T1007
System Service Discovery

Ursnif has gathered information about running services.

T1012
Query Registry

Ursnif has used Reg to query the Registry for installed programs.

T1027.010
Command Obfuscation

Ursnif droppers execute base64 encoded PowerShell commands.

T1027.013
Encrypted/Encoded File

Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands.

T1036.005
Match Legitimate Resource Name or Location

Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names.

T1041
Exfiltration Over C2 Channel

Ursnif has used HTTP POSTs to exfil gathered information.

T1047
Windows Management Instrumentation

Ursnif droppers have used WMI classes to execute PowerShell commands.

T1055.005
Thread Local Storage

Ursnif has injected code into target processes via thread local storage callbacks.

T1055.012
Process Hollowing

Ursnif has used process hollowing to inject into child processes.

T1056.004
Credential API Hooking

Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers.

T1057
Process Discovery

Ursnif has gathered information about running processes.

T1059.001
PowerShell

Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload.

T1059.005
Visual Basic

Ursnif droppers have used VBA macros to download and execute the malware's full executable payload.

T1070.004
File Deletion

Ursnif has deleted data staged in tmp files after exfiltration.

View all 35 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. NJCCIC Ursnif Sept 2016 Open source
    NJCCIC. (2016, September 27). Ursnif. Retrieved September 12, 2024.
  2. ProofPoint Ursnif Aug 2016 Open source
    Proofpoint Staff. (2016, August 25). Nightmare on Tor Street: Ursnif variant Dreambot adds Tor functionality. Retrieved June 5, 2019.
  3. TrendMicro Ursnif Mar 2015 Open source
    Caragay, R. (2015, March 26). URSNIF: The Multifaceted Malware. Retrieved June 5, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.