Mundo, A. (2020, March 26). Ransomware Maze. Retrieved May 18, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
MalwareMaze | Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis. |
| T1027.016 Junk Code Insertion |
MalwareMaze | Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process. |
| T1047 Windows Management Instrumentation |
MalwareMaze | Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network. |
| T1049 System Network Connections Discovery |
MalwareMaze | Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine. |
| T1055.001 Dynamic-link Library Injection |
MalwareMaze | Maze has injected the malware DLL into a target process. |
| T1057 Process Discovery |
MalwareMaze | Maze has gathered all of the running system processes. |
| T1070 Indicator Removal |
MalwareMaze | Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection. |
| T1071.001 Web Protocols |
MalwareMaze | Maze has communicated to hard-coded IP addresses via HTTP. |
| T1082 System Information Discovery |
MalwareMaze | Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function. |
| T1106 Native API |
MalwareMaze | Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others. |
| T1490 Inhibit System Recovery |
MalwareMaze | Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process. |
| T1568 Dynamic Resolution |
MalwareMaze | Maze has forged POST strings with a random choice from a list of possibilities including "forum", "php", "view", etc. while making connection with the C2, hindering detection efforts. |
| T1614.001 System Language Discovery |
MalwareMaze | Maze has checked the language of the machine with function |
| T1685 Disable or Modify Tools |
MalwareMaze | Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.