ATT&CKReferencesCosta AvosLocker May 2022

Costa AvosLocker May 2022

Costa, F. (2022, May 1). RaaS AvosLocker Incident Response Analysis. Retrieved January 11, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples15

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
CampaignC0018

During C0018, the threat actors ran `nslookup` and Advanced IP Scanner on the target network.

T1021.001
Remote Desktop Protocol
CampaignC0018

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

T1027.010
Command Obfuscation
CampaignC0018

During C0018, the threat actors used Base64 to encode their PowerShell scripts.

T1033
System Owner/User Discovery
CampaignC0018

During C0018, the threat actors collected `whoami` information via PowerShell scripts.

T1047
Windows Management Instrumentation
CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1059.001
PowerShell
CampaignC0018

During C0018, the threat actors used encoded PowerShell scripts for execution.

T1071.001
Web Protocols
CampaignC0018

During C0018, the threat actors used HTTP for C2 communications.

T1105
Ingress Tool Transfer
CampaignC0018

During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network.

T1218.011
Rundll32
CampaignC0018

During C0018, the threat actors used `rundll32` to run Mimikatz.

T1219.002
Remote Desktop Software
CampaignC0018

During C0018, the threat actors used AnyDesk to transfer tools between systems.

T1486
Data Encrypted for Impact
CampaignC0018

During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network.

T1570
Lateral Tool Transfer
CampaignC0018

During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy.

T1571
Non-Standard Port
CampaignC0018

During C0018, the threat actors opened a variety of ports, including ports 28035, 32467, 41578, and 46892, to establish RDP connections.

T1588.002
Tool
CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

T1688
Safe Mode Boot
MalwareAvosLocker

AvosLocker can restart a compromised machine in safe mode.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.