Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.011 Fileless Storage |
MalwareREvil | REvil can save encryption parameters and system information in the Registry. |
| T1027.013 Encrypted/Encoded File |
MalwareREvil | REvil has used encrypted strings and configuration files. |
| T1047 Windows Management Instrumentation |
MalwareREvil | REvil can use WMI to monitor for and kill specific processes listed in its configuration file. |
| T1059.001 PowerShell |
MalwareREvil | REvil has used PowerShell to delete volume shadow copies and download files. |
| T1071.001 Web Protocols |
MalwareREvil | REvil has used HTTP and HTTPS in communication with C2. |
| T1082 System Information Discovery |
MalwareREvil | REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
| T1083 File and Directory Discovery |
MalwareREvil | REvil has the ability to identify specific files and directories that are not to be encrypted. |
| T1112 Modify Registry |
MalwareREvil | REvil can modify the Registry to save encryption parameters and system information. |
| T1189 Drive-by Compromise |
MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| T1195.002 Compromise Software Supply Chain |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR. |
| T1485 Data Destruction |
MalwareREvil | REvil has the capability to destroy files and folders. |
| T1490 Inhibit System Recovery |
MalwareREvil | REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features. |
| T1680 Local Storage Discovery |
MalwareREvil | REvil can identify system drive information on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.