Files
Desiree Beck 6ce7ebadf2 Malware types (#140)
* Create malware-types.md

* Update README.md

added link to malware type table.

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update malware-types.md

* Update geneio.md

* Update geneio.md

* Update searchawesome.md

* Update chopstick.md

* Update cozycar.md

* Update gobotkr.md

* Update heriplor.md

* Update hupigon.md

* Update synful-knock.md

* Update mebromi.md

* Update blackenergy.md

* Update cozycar.md

* Update cozycar.md

* Update drovorub.md

* Update evilbunny.md

* Update gamut.md

* Update gobotkr.md

* Update cozycar.md

* Update kovter.md

* Update kraken.md

* Update mazarbot.md

* Update blackenergy.md

* Update matanbuchus.md

* Update yispecter.md

* Update cozycar.md

* Update up007.md

* Update teardrop.md

* Update redhip.md

* Update malware-types.md

* Update rombertik.md

* Update snake.md

* Update snake.md

* Update dark-comet.md

* Update badusb.md

* Update dyepack.md

* Update conti.md

* Update cryptolocker.md

* Update cryptowall.md

* Update locky-bart.md

* Update netwalker.md

* Update samsam.md

* Update wannacry.md

* Update adwind-jrat.md

* Update electrorat.md

* Update gravity-rat.md

* Update poison-ivy.md

* Update terminator.md

* Update clipminer.md

* Update webcobra.md

* Update drovorub.md

* Update dark-comet.md

* Update attor.md

* Update geneio.md

* Update malware-types.md

* Update trickbot.md

* Update dark-comet.md

* Update dnschanger.md

* Update emotet.md

* Update kovter.md

* Update heriplor.md

* Update trickbot.md

* Update ursnif.md

* Update mazarbot.md

* Update shamoon.md

* Update bagle.md

* Update conficker.md

* Update stuxnet.md

* Update vobfus.md

* Newsletter, editing E1510, E1560 (#137) (#138)

* Adding Newsletter

* Create 12182023.md

* Update README.md

---------



* Update e1510 (#134)

* Update clipboard-modification.md

Update to account for updates to T1115.

* Update data-encrypted-for-impact.md

fix parentheses

* Update clipboard-modification.md

* Update data-encrypted-for-impact.md

* Update clipboard-modification.md

* Moving Archive Collected Data to collection, some description updates

* Updating Last Modified

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>

* Newsletter, editing E1510, E1560 (#137) (#139)

* Adding Newsletter

* Create 12182023.md

* Update README.md

---------



* Update e1510 (#134)

* Update clipboard-modification.md

Update to account for updates to T1115.

* Update data-encrypted-for-impact.md

fix parentheses

* Update clipboard-modification.md

* Update data-encrypted-for-impact.md

* Update clipboard-modification.md

* Moving Archive Collected Data to collection, some description updates

* Updating Last Modified

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>

---------

Co-authored-by: Ryan Xu <ryanxu@wustl.edu>
2023-12-20 21:54:25 -05:00

6.0 KiB

ID X0022
Type Trojan (banking trojan)
Aliases Dreambot, Gozi
Platforms Windows
Year 2016
Associated ATT&CK Software Ursnif

Ursnif

Ursnif is a variant of Gozi. It is a banking trojan that uses malware macros to evade sandbox detection.

ATT&CK Techniques

Name Use
Discovery::System Location Discovery::System Language Discovery (T1614.001) Ursnif gets keyboard layouts. [6]

See ATT&CK: Ursnif - Techniques Used.

Enhanced ATT&CK Techniques

Name Use
Persistance::Registry Run Keys / Startup Folder (F0012) The malware adds registry entries to ensure automatic execution at system startup. [4]
Defense Evasion::Hijack Execution Flow (F0015) The malware hooks various DLL exported functions when the DLL component is loaded into their respective browser application to monitor network traffic. [4]
Discovery::System Information Discovery (E1082) The malware uses Window's command prompt commands to gather system info, task list, installed drivers, and installed programs. [4]
Collection::Input Capture (E1056) The malware injects HTML into a browser session to collect sensitive online banking information when the victim performs their online banking. [5]
Defense Evasion::Obfuscated Files or Information (E1027) The malware creates an encrypted Registry key called TorClient to store its data. [2]
Impact::Exploit Kit (E1190) Ursnif is sometimes delivered via exploit kit. [7]
Collection::Keylogging::Polling (F0002.002) Ursnif logs keystrokes via polling. [6]

MBC Behaviors

Name Use
Anti-Behavioral Analysis::Sandbox Detection::Self Check (B0007.007) Ursnif uses malware macros to evade sandbox detection - checking whether the filename contains only hexadecimal characters before the extension. [1]
Execution::Conditional Execution (B0025.004) Macros check if there are at least 50 running processes with a graphical interface, check if a list of blacklisted processes are running, and checks if the application is running in Australia and is NOT affiliated with a select group of networks (Security Research, Hospitals, Universities, Veterans, etc.). [1]
Anti-Behavioral Analysis::Virtual Machine Detection::Check Processes (B0009.004) The malware checks if there are virtual machine processes running (Vbox, vmware, etc). [1]
Command and Control::Domain Name Generation (B0031) Previous interations of Ursnif have used a Domain Name Generation algorithm. [2]
Command and Control::C2 Communication::Authenticate (B0030.011) Ursnif variant Dreambot authenticates and encrypts traffic to the C2 server using TOR. [2]
Anti-Behavioral Analysis::Debugger Detection::TLS Callbacks (B0001.028) The malware manipulates TLS Callbacks while injecting into a child process. [3]
Memory::Change Memory Protection (C0008) The malware changes the PE header of the child process to enable write access to that page and writes 18 bytes of buffer at offset 0x40 from the start of svchost.exe in the target child process. The region protection is changed back to "read only" to avoid suspicion. [3]
Execution::Remote Commands (B0011) The malware commands sent by a remote user can archive/upload files, capture screenshots, clear cookies, download and execute other files, list running processes, reboot the affected system, steal certificates and cookies, update/download a configuration file, and upload a log file which contains stolen information. [5]
Discovery::Code Discovery::Enumerate PE Sections (B0046.001) Ursnif enumerates PE sections. [6]

Indicators of Compromise

SHA256 Hashes

  • 6464cf93832a5188d102cce498b4f3be0525ea1b080fec9c4e12fae912984057
  • 0b05fb5b97bfc3c82f46b8259a88ae656b1ad294e4c1324d8e8ffd59219005ac
  • 9350609c8c806a9c1a667fd53926ea85745e1da239df7f3c2aad3e3527bd48d1

URLS, IPs, and Domains

  • hxxp://62.138.9[.]11/30030u
  • hxxp://62.138.9[.]11/vnc32.dll
  • hxxp://62.138.9[.]11/vnc64.dll
  • 62.138.9[.]9
  • 62.75.195[.]103
  • 62.75.195[.]117
  • ca-tda[.]com
  • au-tdc[.]com
  • au-tda[.]com
  • 109.236.87[.]82:443
  • hxxp://deekayallday[.]com/data/office

References

[1] https://www.proofpoint.com/us/threat-insight/post/ursnif-banking-trojan-campaign-sandbox-evasion-techniques

[2] https://www.proofpoint.com/us/threat-insight/post/ursnif-variant-dreambot-adds-tor-functionality

[3] https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html

[4] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_URSNIF.A2?_ga=2.131425807.1462021705.1559742358-1202584019.1549394279

[5] https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/BKDR_URSNIF.SM?_ga=2.129468940.1462021705.1559742358-1202584019.1549394279

[6] capa v4.0, analyzed at MITRE on 10/12/2022

[7] https://www.cyber.nj.gov/threat-profiles/trojan-variants/ursnif