Malware.View on attack.mitre.org
SynAck is variant of Trojan ransomware targeting mainly English-speaking users since at least fall 2017.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
SynAck enumerates all running services. |
| T1012 Query Registry |
SynAck enumerates Registry keys associated with event logs. |
| T1027 Obfuscated Files or Information |
SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering. |
| T1033 System Owner/User Discovery |
SynAck gathers user names from infected hosts. |
| T1055.013 Process Doppelgänging |
SynAck abuses NTFS transactions to launch and conceal malicious processes. |
| T1057 Process Discovery |
SynAck enumerates all running processes. |
| T1082 System Information Discovery |
SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries. |
| T1083 File and Directory Discovery |
SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1106 Native API |
SynAck parses the export tables of system DLLs to locate and call various Windows API functions. |
| T1112 Modify Registry |
SynAck can manipulate Registry keys. |
| T1486 Data Encrypted for Impact |
SynAck encrypts the victims machine followed by asking the victim to pay a ransom. |
| T1497.001 System Checks |
SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1614.001 System Language Discovery |
SynAck lists all the keyboard layouts installed on the victim’s system using |
| T1685.005 Clear Windows Event Logs |
SynAck clears event logs. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.