Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareAvaddon | Avaddon has used encrypted strings. |
| T1057 Process Discovery |
MalwareAvaddon | Avaddon has collected information about running processes. |
| T1083 File and Directory Discovery |
MalwareAvaddon | Avaddon has searched for specific files prior to encryption. |
| T1112 Modify Registry |
MalwareAvaddon | Avaddon modifies several registry keys for persistence and UAC bypass. |
| T1135 Network Share Discovery |
MalwareAvaddon | Avaddon has enumerated shared folders and mapped volumes. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareAvaddon | Avaddon has decrypted encrypted strings. |
| T1486 Data Encrypted for Impact |
MalwareAvaddon | Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes. |
| T1489 Service Stop |
MalwareAvaddon | Avaddon looks for and attempts to stop database processes. |
| T1490 Inhibit System Recovery |
MalwareAvaddon | Avaddon deletes backups and shadow copies using native system tools. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareAvaddon | Avaddon uses registry run keys for persistence. |
| T1548.002 Bypass User Account Control |
MalwareAvaddon | Avaddon bypasses UAC using the CMSTPLUA COM interface. |
| T1614.001 System Language Discovery |
MalwareAvaddon | Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities. |
| T1685 Disable or Modify Tools |
MalwareAvaddon | Avaddon looks for and attempts to stop anti-malware solutions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.