OopsIE

S0264

Malware.View on attack.mitre.org

About this malware

OopsIE is a Trojan used by OilRig to remotely execute commands as well as upload/download files to/from victims.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1027
Obfuscated Files or Information

OopsIE uses the Confuser protector to obfuscate an embedded .Net Framework assembly used for C2. OopsIE also encodes collected data in hexadecimal format before writing to files on disk and obfuscates strings.

T1027.002
Software Packing

OopsIE uses the SmartAssembly obfuscator to pack an embedded .Net Framework assembly used for C2.

T1030
Data Transfer Size Limits

OopsIE exfiltrates command output and collected files to its C2 server in 1500-byte blocks.

T1041
Exfiltration Over C2 Channel

OopsIE can upload files from the victim's machine to its C2 server.

T1047
Windows Management Instrumentation

OopsIE uses WMI to perform discovery techniques.

T1053.005
Scheduled Task

OopsIE creates a scheduled task to run itself every three minutes.

T1059.003
Windows Command Shell

OopsIE uses the command prompt to execute commands on the victim's machine.

T1059.005
Visual Basic

OopsIE creates and uses a VBScript as part of its persistent execution.

T1070.004
File Deletion

OopsIE has the capability to delete files and scripts from the victim's machine.

T1071.001
Web Protocols

OopsIE uses HTTP for C2 communications.

T1074.001
Local Data Staging

OopsIE stages the output from command execution and collected files in specific folders before exfiltration.

T1082
System Information Discovery

OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks.

T1105
Ingress Tool Transfer

OopsIE can download files from its C2 server to the victim's machine.

T1124
System Time Discovery

OopsIE checks to see if the system is configured with "Daylight" time and checks for a specific region to be set for the timezone.

T1132.001
Standard Encoding

OopsIE encodes data in hexadecimal format over the C2 channel.

View all 19 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit 42 OopsIE! Feb 2018 Open source
    Lee, B., Falcone, R. (2018, February 23). OopsIE! OilRig Uses ThreeDollars to Deliver New Trojan. Retrieved July 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.