ATT&CKReferencesPalo Alto OilRig Oct 2016

Palo Alto OilRig Oct 2016

Grunzweig, J. and Falcone, R.. (2016, October 4). OilRig Malware Campaign Updates Toolset and Expands Targets. Retrieved May 3, 2017.

Open the source

Techniques1

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupOilRig

OilRig has run ipconfig /all on a victim.

T1033
System Owner/User Discovery
GroupOilRig

OilRig has run whoami on a victim.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupOilRig

OilRig has exfiltrated data via Microsoft Exchange and over FTP separately from its primary C2 channel over DNS.

T1082
System Information Discovery
GroupOilRig

OilRig has run hostname and systeminfo on a victim.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.