ATT&CKReferencesAntiy CERT Ramsay April 2020

Antiy CERT Ramsay April 2020

Antiy CERT. (2020, April 20). Analysis of Ramsay components of Darkhotel's infiltration and isolation network. Retrieved March 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRamsay

Ramsay can collect Microsoft Word documents from the target's file system, as well as .txt, .doc, and .xls files from the Internet Explorer cache.

T1016
System Network Configuration Discovery
MalwareRamsay

Ramsay can use ipconfig and Arp to collect network configuration information, including routing information and ARP tables.

T1027.003
Steganography
MalwareRamsay

Ramsay has PE data embedded within JPEG files contained within Word documents.

T1036.005
Match Legitimate Resource Name or Location
MalwareRamsay

Ramsay has masqueraded as a 7zip installer.

T1046
Network Service Discovery
MalwareRamsay

Ramsay can scan for systems that are vulnerable to the EternalBlue exploit.

T1049
System Network Connections Discovery
MalwareRamsay

Ramsay can use netstat to enumerate network connections.

T1057
Process Discovery
MalwareRamsay

Ramsay can gather a list of running processes by using Tasklist.

T1059.005
Visual Basic
MalwareRamsay

Ramsay has included embedded Visual Basic scripts in malicious documents.

T1071.001
Web Protocols
MalwareRamsay

Ramsay has used HTTP for C2.

T1074.001
Local Data Staging
MalwareRamsay

Ramsay can stage data prior to exfiltration in %APPDATA%\Microsoft\UserSetting and %APPDATA%\Microsoft\UserSetting\MediaCache.

T1083
File and Directory Discovery
MalwareRamsay

Ramsay can collect directory and file lists.

T1113
Screen Capture
MalwareRamsay

Ramsay can take screenshots every 30 seconds as well as when an external removable storage device is connected.

T1120
Peripheral Device Discovery
MalwareRamsay

Ramsay can scan for removable media which may contain documents for collection.

T1132.001
Standard Encoding
MalwareRamsay

Ramsay has used base64 to encode its C2 traffic.

T1135
Network Share Discovery
MalwareRamsay

Ramsay can scan for network drives which may contain documents for collection.

T1203
Exploitation for Client Execution
MalwareRamsay

Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570.

T1204.002
Malicious File
MalwareRamsay

Ramsay has been executed through malicious e-mail attachments.

T1547.001
Registry Run Keys / Startup Folder
MalwareRamsay

Ramsay has created Registry Run keys to establish persistence.

T1548.002
Bypass User Account Control
MalwareRamsay

Ramsay can use UACMe for privilege escalation.

T1560.001
Archive via Utility
MalwareRamsay

Ramsay can compress and archive collected files using WinRAR.

T1566.001
Spearphishing Attachment
MalwareRamsay

Ramsay has been distributed through spearphishing emails with malicious attachments.

T1680
Local Storage Discovery
MalwareRamsay

Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.