Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareQakBot | QakBot can use |
| T1027.001 Binary Padding |
MalwareQakBot | QakBot can use large file sizes to evade detection. |
| T1027.003 Steganography |
MalwareProLock | ProLock can use .jpg and .bmp files to store its payload. |
| T1027.011 Fileless Storage |
MalwareQakBot | QakBot can store its configuration information in a randomly named subkey under |
| T1036.008 Masquerade File Type |
MalwareQakBot | The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon. |
| T1047 Windows Management Instrumentation |
MalwareProLock | ProLock can use WMIC to execute scripts on targeted hosts. |
| T1053.005 Scheduled Task |
MalwareQakBot | QakBot has the ability to create scheduled tasks for persistence. |
| T1059.001 PowerShell |
MalwareQakBot | QakBot can use PowerShell to download and execute payloads. |
| T1059.005 Visual Basic |
MalwareQakBot | QakBot can use VBS to download and execute malicious files. |
| T1068 Exploitation for Privilege Escalation |
MalwareProLock | ProLock can use CVE-2019-0859 to escalate privileges on a compromised host. |
| T1070.004 File Deletion |
MalwareQakBot | QakBot can delete folders and files including overwriting its executable with legitimate programs. |
| T1070.004 File Deletion |
MalwareProLock | ProLock can remove files containing its payload after they are executed. |
| T1082 System Information Discovery |
MalwareQakBot | QakBot can collect system information including the OS version and domain on a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareQakBot | QakBot has the ability to download additional components and malware. |
| T1112 Modify Registry |
MalwareQakBot | QakBot can modify the Registry to store its configuration information in a randomly named subkey under |
| T1197 BITS Jobs |
MalwareProLock | ProLock can use BITS jobs to download its malicious payload. |
| T1204.001 Malicious Link |
MalwareQakBot | QakBot has gained execution through users opening malicious links. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1486 Data Encrypted for Impact |
MalwareProLock | ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024. |
| T1490 Inhibit System Recovery |
MalwareProLock | ProLock can use vssadmin.exe to remove volume shadow copies. |
| T1518 Software Discovery |
MalwareQakBot | QakBot can enumerate a list of installed programs. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareQakBot | QakBot can maintain persistence by creating an auto-run Registry key. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1566.002 Spearphishing Link |
MalwareQakBot | QakBot has spread through emails with malicious links. |
| T1685 Disable or Modify Tools |
MalwareQakBot | QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.