ATT&CKReferencesKaspersky Lab SynAck May 2018

Kaspersky Lab SynAck May 2018

Bettencourt, J. (2018, May 7). Kaspersky Lab finds new variant of SynAck ransomware using sophisticated Doppelgänging technique. Retrieved May 24, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareSynAck

SynAck enumerates all running services.

T1027
Obfuscated Files or Information
MalwareSynAck

SynAck payloads are obfuscated prior to compilation to inhibit analysis and/or reverse engineering.

T1055.013
Process Doppelgänging
MalwareSynAck

SynAck abuses NTFS transactions to launch and conceal malicious processes.

T1057
Process Discovery
MalwareSynAck

SynAck enumerates all running processes.

T1083
File and Directory Discovery
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

T1106
Native API
MalwareSynAck

SynAck parses the export tables of system DLLs to locate and call various Windows API functions.

T1497.001
System Checks
MalwareSynAck

SynAck checks its directory location in an attempt to avoid launching in a sandbox.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.