C0015

C0015

Campaign, Aug 2021 to Aug 2021.View on attack.mitre.org

About this campaign

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1005
Data from Local System

During C0015, the threat actors obtained files and data from the compromised network.

T1016
System Network Configuration Discovery

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.

T1018
Remote System Discovery

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.

T1021.001
Remote Desktop Protocol

During C0015, the threat actors used RDP to access specific network hosts of interest.

T1027
Obfuscated Files or Information

During C0015, the threat actors used Base64-encoded strings.

T1030
Data Transfer Size Limits

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.

T1036
Masquerading

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.

T1039
Data from Network Shared Drive

During C0015, the threat actors collected files from network shared drives prior to network encryption.

T1047
Windows Management Instrumentation

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

T1055.001
Dynamic-link Library Injection

During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process.

T1057
Process Discovery

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

T1059.003
Windows Command Shell

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.

T1059.005
Visual Basic

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.

T1059.007
JavaScript

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.

T1069.001
Local Groups

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.

View all 34 procedure examples

Attributed groups0

MITRE does not attribute this campaign to a group.

Software5

References1

  1. DFIR Conti Bazar Nov 2021 Open source
    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.