The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1021.002 SMB/Windows Admin Shares |
GroupWizard Spider | Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement. |
| T1027.010 Command Obfuscation |
GroupWizard Spider | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1047 Windows Management Instrumentation |
MalwareBazar | Bazar can execute a WMI query to gather information about the installed antivirus engine. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupWizard Spider | Wizard Spider has exfiltrated victim information using FTP. |
| T1059.003 Windows Command Shell |
GroupWizard Spider | Wizard Spider has used `cmd.exe` to execute commands on a victim's machine. |
| T1082 System Information Discovery |
GroupWizard Spider | Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory. |
| T1087.002 Domain Account |
MalwareBazar | Bazar has the ability to identify domain administrator accounts. |
| T1087.002 Domain Account |
GroupWizard Spider | Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data. |
| T1210 Exploitation of Remote Services |
GroupWizard Spider | Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities. |
| T1482 Domain Trust Discovery |
ToolRubeus | Rubeus can gather information about domain trusts. |
| T1489 Service Stop |
GroupWizard Spider | Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption. |
| T1518.001 Security Software Discovery |
GroupWizard Spider | Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine. |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1558.004 AS-REP Roasting |
ToolRubeus | Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting. |
| T1569.002 Service Execution |
GroupWizard Spider | Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.