Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1027.003 Steganography |
ProLock can use .jpg and .bmp files to store its payload. |
| T1047 Windows Management Instrumentation |
ProLock can use WMIC to execute scripts on targeted hosts. |
| T1068 Exploitation for Privilege Escalation |
ProLock can use CVE-2019-0859 to escalate privileges on a compromised host. |
| T1070.004 File Deletion |
ProLock can remove files containing its payload after they are executed. |
| T1197 BITS Jobs |
ProLock can use BITS jobs to download its malicious payload. |
| T1486 Data Encrypted for Impact |
ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024. |
| T1490 Inhibit System Recovery |
ProLock can use vssadmin.exe to remove volume shadow copies. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.