Baskin, B. (2020, July 8). TAU Threat Discovery: Conti Ransomware. Retrieved February 17, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareConti | Conti can retrieve the ARP cache from the local system by using the |
| T1021.002 SMB/Windows Admin Shares |
MalwareConti | Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network. |
| T1027 Obfuscated Files or Information |
MalwareConti | Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls. |
| T1049 System Network Connections Discovery |
MalwareConti | Conti can enumerate routine network connections from a compromised host. |
| T1055.001 Dynamic-link Library Injection |
MalwareConti | Conti has loaded an encrypted DLL into memory and then executes it. |
| T1057 Process Discovery |
MalwareConti | Conti can enumerate through all open processes to search for any that have the string “sql” in their process name. |
| T1059.003 Windows Command Shell |
MalwareConti | Conti can utilize command line options to allow an attacker control over how it scans and encrypts files. |
| T1080 Taint Shared Content |
MalwareConti | Conti can spread itself by infecting other remote machines via network shared drives. |
| T1083 File and Directory Discovery |
MalwareConti | Conti can discover files on a local system. |
| T1106 Native API |
MalwareConti | Conti has used API calls during execution. |
| T1135 Network Share Discovery |
MalwareConti | Conti can enumerate remote open SMB network shares using |
| T1140 Deobfuscate/Decode Files or Information |
MalwareConti | Conti has decrypted its payload using a hardcoded AES-256 key. |
| T1486 Data Encrypted for Impact |
MalwareConti | Conti can use |
| T1489 Service Stop |
MalwareConti | Conti can stop up to 146 Windows services related to security, backup, database, and email solutions through the use of |
| T1490 Inhibit System Recovery |
MalwareConti | Conti can delete Windows Volume Shadow Copies using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.