Malware.View on attack.mitre.org
Ursnif is a banking trojan and variant of the Gozi malware observed being spread through various automated exploit kits, Spearphishing Attachments, and malicious links. Ursnif is associated primarily with data theft, but variants also include components (backdoors, spyware, file injectors, etc.) capable of a wide variety of behaviors.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Ursnif has collected files from victim machines, including certificates and cookies. |
| T1007 System Service Discovery |
Ursnif has gathered information about running services. |
| T1012 Query Registry |
Ursnif has used Reg to query the Registry for installed programs. |
| T1027.010 Command Obfuscation |
Ursnif droppers execute base64 encoded PowerShell commands. |
| T1027.013 Encrypted/Encoded File |
Ursnif has used an XOR-based algorithm to encrypt Tor clients dropped to disk. Ursnif droppers have also been delivered as password-protected zip files that execute base64 encoded PowerShell commands. |
| T1036.005 Match Legitimate Resource Name or Location |
Ursnif has used strings from legitimate system files and existing folders for its file, folder, and Registry entry names. |
| T1041 Exfiltration Over C2 Channel |
Ursnif has used HTTP POSTs to exfil gathered information. |
| T1047 Windows Management Instrumentation |
Ursnif droppers have used WMI classes to execute PowerShell commands. |
| T1055.005 Thread Local Storage |
Ursnif has injected code into target processes via thread local storage callbacks. |
| T1055.012 Process Hollowing |
Ursnif has used process hollowing to inject into child processes. |
| T1056.004 Credential API Hooking |
Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers. |
| T1057 Process Discovery |
Ursnif has gathered information about running processes. |
| T1059.001 PowerShell |
Ursnif droppers have used PowerShell in download cradles to download and execute the malware's full executable payload. |
| T1059.005 Visual Basic |
Ursnif droppers have used VBA macros to download and execute the malware's full executable payload. |
| T1070.004 File Deletion |
Ursnif has deleted data staged in tmp files after exfiltration. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.