Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
MalwareNotPetya | NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareNotPetya | NotPetya can use PsExec, which interacts with the |
| T1036 Masquerading |
MalwareNotPetya | |
| T1047 Windows Management Instrumentation |
MalwareNotPetya | NotPetya can use |
| T1053.005 Scheduled Task |
MalwareNotPetya | NotPetya creates a task to reboot the system one hour after infection. |
| T1078.003 Local Accounts |
MalwareNotPetya | NotPetya can use valid credentials with PsExec or |
| T1210 Exploitation of Remote Services |
MalwareNotPetya | NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network. |
| T1218.011 Rundll32 |
MalwareNotPetya | NotPetya uses |
| T1486 Data Encrypted for Impact |
MalwareNotPetya | NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA. |
| T1529 System Shutdown/Reboot |
MalwareNotPetya | NotPetya will reboot the system one hour after infection. |
| T1569.002 Service Execution |
MalwareNotPetya | NotPetya can use PsExec to help propagate itself across a network. |
| T1685.005 Clear Windows Event Logs |
MalwareNotPetya | NotPetya uses |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.