ATT&CKReferencesFireEye FiveHands April 2021

FireEye FiveHands April 2021

McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software4

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1027.013
Encrypted/Encoded File
MalwareFIVEHANDS

The FIVEHANDS payload is encrypted with AES-128.

T1047
Windows Management Instrumentation
MalwareHELLOKITTY

HELLOKITTY can use WMI to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareFIVEHANDS

FIVEHANDS can use WMI to delete files on a target machine.

T1047
Windows Management Instrumentation
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use WMI to delete volume shadow copies.

T1057
Process Discovery
MalwareHELLOKITTY

HELLOKITTY can search for specific processes to terminate.

T1057
Process Discovery
MalwareSombRAT

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1059
Command and Scripting Interpreter
MalwareFIVEHANDS

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

T1071.001
Web Protocols
MalwareDEATHRANSOM

DEATHRANSOM can use HTTPS to download files.

T1071.004
DNS
MalwareSombRAT

SombRAT can communicate over DNS with the C2 server.

T1083
File and Directory Discovery
MalwareDEATHRANSOM

DEATHRANSOM can use loop operations to enumerate directories on a compromised host.

T1095
Non-Application Layer Protocol
MalwareSombRAT

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

T1105
Ingress Tool Transfer
MalwareSombRAT

SombRAT has the ability to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwareDEATHRANSOM

DEATHRANSOM can download files to a compromised host.

T1135
Network Share Discovery
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use loop operations to enumerate network resources.

T1135
Network Share Discovery
MalwareHELLOKITTY

HELLOKITTY has the ability to enumerate network resources.

T1140
Deobfuscate/Decode Files or Information
MalwareFIVEHANDS

FIVEHANDS has the ability to decrypt its payload prior to execution.

T1486
Data Encrypted for Impact
MalwareFIVEHANDS

FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom.

T1486
Data Encrypted for Impact
MalwareDEATHRANSOM

DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment.

T1486
Data Encrypted for Impact
MalwareHELLOKITTY

HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom.

T1490
Inhibit System Recovery
MalwareDEATHRANSOM

DEATHRANSOM can delete volume shadow copies on compromised hosts.

T1490
Inhibit System Recovery
MalwareFIVEHANDS

FIVEHANDS has the ability to delete volume shadow copies on compromised hosts.

T1490
Inhibit System Recovery
MalwareHELLOKITTY

HELLOKITTY can delete volume shadow copies on compromised hosts.

T1564.010
Process Argument Spoofing
MalwareSombRAT

SombRAT has the ability to modify its process memory to hide process command-line arguments.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

T1614.001
System Language Discovery
MalwareDEATHRANSOM

Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit.

T1680
Local Storage Discovery
MalwareHELLOKITTY

HELLOKITTY can enumerate logical drives on a target system.

T1680
Local Storage Discovery
MalwareDEATHRANSOM

DEATHRANSOM can enumerate logical drives on a target system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.