Turla__2014__circl-tr25-analysis-turla-pfinet-snake-uroburos.pdf
ID: adfc70bd-2067-4636-9a8e-cda3e7f77dff
STIX ID: report--adfc70bd-2067-4636-9a8e-cda3e7f77dff
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
TR-25 analyzes the Uroburos (Turla/Snake/Uroburos) rootkit, summarizing static and dynamic analyses of samples A–H. It details a multi‑component infection with a kernel‑mode driver (usbdev.sys) and several userland modules (inetpub.dll, cryptoapi.dll, config.txt), persistence via services, resource‑driven drops, inter‑process communication, mutexes for access control, a virtual file system, and decryption routines; the report also documents IOCs, transport modules (tcp/np/frag/m2b), check‑in messages, and extensive logging, indicating a sophisticated state‑sponsored malware framework attributed to the Turla group.
