ATT&CKReferencesMalwarebytes AvosLocker Jul 2021

Malwarebytes AvosLocker Jul 2021

Hasherezade. (2021, July 23). AvosLocker enters the ransomware scene, asks for partners. Retrieved January 11, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareAvosLocker

AvosLocker has used XOR-encoded strings.

T1027.007
Dynamic API Resolution
MalwareAvosLocker

AvosLocker has used obfuscated API calls that are retrieved by their checksums.

T1057
Process Discovery
MalwareAvosLocker

AvosLocker has discovered system processes by calling `RmGetList`.

T1083
File and Directory Discovery
MalwareAvosLocker

AvosLocker has searched for files and directories on a compromised network.

T1106
Native API
MalwareAvosLocker

AvosLocker has used a variety of Windows API calls, including `NtCurrentPeb` and `GetLogicalDrives`.

T1124
System Time Discovery
MalwareAvosLocker

AvosLocker has checked the system time before and after encryption.

T1135
Network Share Discovery
MalwareAvosLocker

AvosLocker has enumerated shared drives on a compromised network.

T1140
Deobfuscate/Decode Files or Information
MalwareAvosLocker

AvosLocker has deobfuscated XOR-encoded strings.

T1486
Data Encrypted for Impact
MalwareAvosLocker

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

T1489
Service Stop
MalwareAvosLocker

AvosLocker has terminated specific processes before encryption.

T1564.003
Hidden Window
MalwareAvosLocker

AvosLocker has hidden its console window by using the `ShowWindow` API function.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.