ATT&CKReferencesUS-CERT NotPetya 2017

US-CERT NotPetya 2017

US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareNotPetya

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareNotPetya

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.

T1047
Windows Management Instrumentation
MalwareNotPetya

NotPetya can use wmic to help propagate itself across a network.

T1078.003
Local Accounts
MalwareNotPetya

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.

T1210
Exploitation of Remote Services
MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1486
Data Encrypted for Impact
MalwareNotPetya

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.

T1569.002
Service Execution
MalwareNotPetya

NotPetya can use PsExec to help propagate itself across a network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.