ATT&CKReferencesGroup IB Ransomware September 2020

Group IB Ransomware September 2020

Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples25

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1027.001
Binary Padding
MalwareQakBot

QakBot can use large file sizes to evade detection.

T1027.003
Steganography
MalwareProLock

ProLock can use .jpg and .bmp files to store its payload.

T1027.011
Fileless Storage
MalwareQakBot

QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1036.008
Masquerade File Type
MalwareQakBot

The QakBot payload has been disguised as a PNG file and hidden within LNK files using a Microsoft File Explorer icon.

T1047
Windows Management Instrumentation
MalwareProLock

ProLock can use WMIC to execute scripts on targeted hosts.

T1053.005
Scheduled Task
MalwareQakBot

QakBot has the ability to create scheduled tasks for persistence.

T1059.001
PowerShell
MalwareQakBot

QakBot can use PowerShell to download and execute payloads.

T1059.005
Visual Basic
MalwareQakBot

QakBot can use VBS to download and execute malicious files.

T1068
Exploitation for Privilege Escalation
MalwareProLock

ProLock can use CVE-2019-0859 to escalate privileges on a compromised host.

T1070.004
File Deletion
MalwareQakBot

QakBot can delete folders and files including overwriting its executable with legitimate programs.

T1070.004
File Deletion
MalwareProLock

ProLock can remove files containing its payload after they are executed.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1105
Ingress Tool Transfer
MalwareQakBot

QakBot has the ability to download additional components and malware.

T1112
Modify Registry
MalwareQakBot

QakBot can modify the Registry to store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.

T1197
BITS Jobs
MalwareProLock

ProLock can use BITS jobs to download its malicious payload.

T1204.001
Malicious Link
MalwareQakBot

QakBot has gained execution through users opening malicious links.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1486
Data Encrypted for Impact
MalwareProLock

ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024.

T1490
Inhibit System Recovery
MalwareProLock

ProLock can use vssadmin.exe to remove volume shadow copies.

T1518
Software Discovery
MalwareQakBot

QakBot can enumerate a list of installed programs.

T1547.001
Registry Run Keys / Startup Folder
MalwareQakBot

QakBot can maintain persistence by creating an auto-run Registry key.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1566.002
Spearphishing Link
MalwareQakBot

QakBot has spread through emails with malicious links.

T1685
Disable or Modify Tools
MalwareQakBot

QakBot has the ability to modify the Registry to add its binaries to the Windows Defender exclusion list.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.