Campaign, Aug 2021 to Aug 2021.View on attack.mitre.org
C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
During C0015, the threat actors obtained files and data from the compromised network. |
| T1016 System Network Configuration Discovery |
During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host. |
| T1018 Remote System Discovery |
During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration. |
| T1021.001 Remote Desktop Protocol |
During C0015, the threat actors used RDP to access specific network hosts of interest. |
| T1027 Obfuscated Files or Information |
During C0015, the threat actors used Base64-encoded strings. |
| T1030 Data Transfer Size Limits |
During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration. |
| T1036 Masquerading |
During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file. |
| T1039 Data from Network Shared Drive |
During C0015, the threat actors collected files from network shared drives prior to network encryption. |
| T1047 Windows Management Instrumentation |
During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host. |
| T1055.001 Dynamic-link Library Injection |
During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process. |
| T1057 Process Discovery |
During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes. |
| T1059.003 Windows Command Shell |
During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries. |
| T1059.005 Visual Basic |
During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code. |
| T1059.007 JavaScript |
During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code. |
| T1069.001 Local Groups |
During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.