ATT&CKReferencesCISA AR21-126A FIVEHANDS May 2021

CISA AR21-126A FIVEHANDS May 2021

CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareSombRAT

SombRAT has collected data and files from a compromised host.

T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1027.013
Encrypted/Encoded File
MalwareFIVEHANDS

The FIVEHANDS payload is encrypted with AES-128.

T1033
System Owner/User Discovery
MalwareSombRAT

SombRAT can execute getinfo to identify the username on a compromised host.

T1036
Masquerading
MalwareSombRAT

SombRAT can use a legitimate process name to hide itself.

T1047
Windows Management Instrumentation
MalwareFIVEHANDS

FIVEHANDS can use WMI to delete files on a target machine.

T1057
Process Discovery
MalwareSombRAT

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1083
File and Directory Discovery
MalwareFIVEHANDS

FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions.

T1090
Proxy
MalwareSombRAT

SombRAT has the ability to use an embedded SOCKS proxy in C2 communications.

T1105
Ingress Tool Transfer
MalwareSombRAT

SombRAT has the ability to download and execute additional payloads.

T1124
System Time Discovery
MalwareSombRAT

SombRAT can execute getinfo to discover the current time on a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwareSombRAT

SombRAT can run upload to decrypt and upload files from storage.

T1140
Deobfuscate/Decode Files or Information
MalwareFIVEHANDS

FIVEHANDS has the ability to decrypt its payload prior to execution.

T1486
Data Encrypted for Impact
MalwareFIVEHANDS

FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom.

T1490
Inhibit System Recovery
MalwareFIVEHANDS

FIVEHANDS has the ability to delete volume shadow copies on compromised hosts.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.