Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareBabuk | Babuk has the ability to check running processes on a targeted system. |
| T1059.003 Windows Command Shell |
MalwareSeth-Locker | Seth-Locker can execute commands via the command line shell. |
| T1083 File and Directory Discovery |
MalwareBabuk | Babuk has the ability to enumerate files on a targeted system. |
| T1105 Ingress Tool Transfer |
MalwareSeth-Locker | Seth-Locker has the ability to download and execute files on a compromised host. |
| T1486 Data Encrypted for Impact |
MalwareSeth-Locker | Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth. |
| T1486 Data Encrypted for Impact |
MalwareBabuk | Babuk can use ChaCha8 and ECDH to encrypt data. |
| T1489 Service Stop |
MalwareBabuk | Babuk can stop specific services related to backups. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.