McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareSombRAT | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1027.013 Encrypted/Encoded File |
MalwareFIVEHANDS | The FIVEHANDS payload is encrypted with AES-128. |
| T1047 Windows Management Instrumentation |
MalwareHELLOKITTY | HELLOKITTY can use WMI to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareFIVEHANDS | FIVEHANDS can use WMI to delete files on a target machine. |
| T1047 Windows Management Instrumentation |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use WMI to delete volume shadow copies. |
| T1057 Process Discovery |
MalwareHELLOKITTY | HELLOKITTY can search for specific processes to terminate. |
| T1057 Process Discovery |
MalwareSombRAT | SombRAT can use the |
| T1059 Command and Scripting Interpreter |
MalwareFIVEHANDS | FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| T1071.001 Web Protocols |
MalwareDEATHRANSOM | DEATHRANSOM can use HTTPS to download files. |
| T1071.004 DNS |
MalwareSombRAT | SombRAT can communicate over DNS with the C2 server. |
| T1083 File and Directory Discovery |
MalwareDEATHRANSOM | DEATHRANSOM can use loop operations to enumerate directories on a compromised host. |
| T1095 Non-Application Layer Protocol |
MalwareSombRAT | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareSombRAT | SombRAT has the ability to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwareDEATHRANSOM | DEATHRANSOM can download files to a compromised host. |
| T1135 Network Share Discovery |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use loop operations to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareHELLOKITTY | HELLOKITTY has the ability to enumerate network resources. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFIVEHANDS | FIVEHANDS has the ability to decrypt its payload prior to execution. |
| T1486 Data Encrypted for Impact |
MalwareFIVEHANDS | FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom. |
| T1486 Data Encrypted for Impact |
MalwareDEATHRANSOM | DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment. |
| T1486 Data Encrypted for Impact |
MalwareHELLOKITTY | HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom. |
| T1490 Inhibit System Recovery |
MalwareDEATHRANSOM | DEATHRANSOM can delete volume shadow copies on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareFIVEHANDS | FIVEHANDS has the ability to delete volume shadow copies on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareHELLOKITTY | HELLOKITTY can delete volume shadow copies on compromised hosts. |
| T1564.010 Process Argument Spoofing |
MalwareSombRAT | SombRAT has the ability to modify its process memory to hide process command-line arguments. |
| T1573.002 Asymmetric Cryptography |
MalwareSombRAT | SombRAT can SSL encrypt C2 traffic. |
| T1614.001 System Language Discovery |
MalwareDEATHRANSOM | Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit. |
| T1680 Local Storage Discovery |
MalwareHELLOKITTY | HELLOKITTY can enumerate logical drives on a target system. |
| T1680 Local Storage Discovery |
MalwareDEATHRANSOM | DEATHRANSOM can enumerate logical drives on a target system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.