ATT&CKReferencesSecureList SynAck Doppelgänging May 2018

SecureList SynAck Doppelgänging May 2018

Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareSynAck

SynAck enumerates all running services.

T1012
Query Registry
MalwareSynAck

SynAck enumerates Registry keys associated with event logs.

T1027
Obfuscated Files or Information
MalwareSynAck

SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering.

T1033
System Owner/User Discovery
MalwareSynAck

SynAck gathers user names from infected hosts.

T1055.013
Process Doppelgänging
MalwareSynAck

SynAck abuses NTFS transactions to launch and conceal malicious processes.

T1057
Process Discovery
MalwareSynAck

SynAck enumerates all running processes.

T1082
System Information Discovery
MalwareSynAck

SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries.

T1083
File and Directory Discovery
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1106
Native API
MalwareSynAck

SynAck parses the export tables of system DLLs to locate and call various Windows API functions.

T1112
Modify Registry
MalwareSynAck

SynAck can manipulate Registry keys.

T1486
Data Encrypted for Impact
MalwareSynAck

SynAck encrypts the victims machine followed by asking the victim to pay a ransom.

T1497.001
System Checks
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1614.001
System Language Discovery
MalwareSynAck

SynAck lists all the keyboard layouts installed on the victim’s system using GetKeyboardLayoutList API and checks against a hardcoded language code list. If a match if found, SynAck sleeps for 300 seconds and then exits without encrypting files.

T1685.005
Clear Windows Event Logs
MalwareSynAck

SynAck clears event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.