Ivanov, A. et al. (2018, May 7). SynAck targeted ransomware uses the Doppelgänging technique. Retrieved May 22, 2018.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareSynAck | SynAck enumerates all running services. |
| T1012 Query Registry |
MalwareSynAck | SynAck enumerates Registry keys associated with event logs. |
| T1027 Obfuscated Files or Information |
MalwareSynAck | SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering. |
| T1033 System Owner/User Discovery |
MalwareSynAck | SynAck gathers user names from infected hosts. |
| T1055.013 Process Doppelgänging |
MalwareSynAck | SynAck abuses NTFS transactions to launch and conceal malicious processes. |
| T1057 Process Discovery |
MalwareSynAck | SynAck enumerates all running processes. |
| T1082 System Information Discovery |
MalwareSynAck | SynAck gathers computer names, OS version info, and also checks installed keyboard layouts to estimate if it has been launched from a certain list of countries. |
| T1083 File and Directory Discovery |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1106 Native API |
MalwareSynAck | SynAck parses the export tables of system DLLs to locate and call various Windows API functions. |
| T1112 Modify Registry |
MalwareSynAck | SynAck can manipulate Registry keys. |
| T1486 Data Encrypted for Impact |
MalwareSynAck | SynAck encrypts the victims machine followed by asking the victim to pay a ransom. |
| T1497.001 System Checks |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1614.001 System Language Discovery |
MalwareSynAck | SynAck lists all the keyboard layouts installed on the victim’s system using |
| T1685.005 Clear Windows Event Logs |
MalwareSynAck | SynAck clears event logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.