Bettencourt, J. (2018, May 7). Kaspersky Lab finds new variant of SynAck ransomware using sophisticated Doppelgänging technique. Retrieved May 24, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareSynAck | SynAck enumerates all running services. |
| T1027 Obfuscated Files or Information |
MalwareSynAck | SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering. |
| T1055.013 Process Doppelgänging |
MalwareSynAck | SynAck abuses NTFS transactions to launch and conceal malicious processes. |
| T1057 Process Discovery |
MalwareSynAck | SynAck enumerates all running processes. |
| T1083 File and Directory Discovery |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1106 Native API |
MalwareSynAck | SynAck parses the export tables of system DLLs to locate and call various Windows API functions. |
| T1497.001 System Checks |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.