Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
Maze has decrypted strings and other important information during the encryption process. Maze also calls certain functions dynamically to hinder analysis. |
| T1027.016 Junk Code Insertion |
Maze has inserted large blocks of junk code, including some components to decrypt strings and other important information for later in the encryption process. |
| T1036.004 Masquerade Task or Service |
Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware. |
| T1047 Windows Management Instrumentation |
Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network. |
| T1049 System Network Connections Discovery |
Maze has used the "WNetOpenEnumW", "WNetEnumResourceW”, “WNetCloseEnum” and “WNetAddConnection2W” functions to enumerate the network resources on the infected machine. |
| T1053.005 Scheduled Task |
Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time. |
| T1055.001 Dynamic-link Library Injection |
Maze has injected the malware DLL into a target process. |
| T1057 Process Discovery |
Maze has gathered all of the running system processes. |
| T1059.003 Windows Command Shell |
The Maze encryption process has used batch scripts with various commands. |
| T1070 Indicator Removal |
Maze has used the “Wow64RevertWow64FsRedirection” function following attempts to delete the shadow volumes, in order to leave the system in the same state as it was prior to redirection. |
| T1071.001 Web Protocols |
Maze has communicated to hard-coded IP addresses via HTTP. |
| T1082 System Information Discovery |
Maze has checked the language of the infected system using the "GetUSerDefaultUILanguage" function. |
| T1106 Native API |
Maze has used several Windows API functions throughout the encryption process including IsDebuggerPresent, TerminateProcess, Process32FirstW, among others. |
| T1218.007 Msiexec |
Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using |
| T1486 Data Encrypted for Impact |
Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.