ATT&CKReferencesArxiv Avaddon Feb 2021

Arxiv Avaddon Feb 2021

Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareAvaddon

Avaddon has used encrypted strings.

T1057
Process Discovery
MalwareAvaddon

Avaddon has collected information about running processes.

T1083
File and Directory Discovery
MalwareAvaddon

Avaddon has searched for specific files prior to encryption.

T1112
Modify Registry
MalwareAvaddon

Avaddon modifies several registry keys for persistence and UAC bypass.

T1135
Network Share Discovery
MalwareAvaddon

Avaddon has enumerated shared folders and mapped volumes.

T1140
Deobfuscate/Decode Files or Information
MalwareAvaddon

Avaddon has decrypted encrypted strings.

T1486
Data Encrypted for Impact
MalwareAvaddon

Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.

T1489
Service Stop
MalwareAvaddon

Avaddon looks for and attempts to stop database processes.

T1490
Inhibit System Recovery
MalwareAvaddon

Avaddon deletes backups and shadow copies using native system tools.

T1547.001
Registry Run Keys / Startup Folder
MalwareAvaddon

Avaddon uses registry run keys for persistence.

T1548.002
Bypass User Account Control
MalwareAvaddon

Avaddon bypasses UAC using the CMSTPLUA COM interface.

T1614.001
System Language Discovery
MalwareAvaddon

Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.

T1685
Disable or Modify Tools
MalwareAvaddon

Avaddon looks for and attempts to stop anti-malware solutions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.