Security Lab. (2020, June 5). Avaddon: From seeking affiliates to in-the-wild in 2 days. Retrieved August 19, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareAvaddon | Avaddon uses wmic.exe to delete shadow copies. |
| T1059.007 JavaScript |
MalwareAvaddon | Avaddon has been executed through a malicious JScript downloader. |
| T1106 Native API |
MalwareAvaddon | Avaddon has used the Windows Crypto API to generate an AES key. |
| T1490 Inhibit System Recovery |
MalwareAvaddon | Avaddon deletes backups and shadow copies using native system tools. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.