Lee, S. (2019, May 17). CB TAU Threat Intelligence Notification: RobbinHood Ransomware Stops 181 Windows Services Before Encryption. Retrieved July 29, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.003 Windows Command Shell |
MalwareRobbinHood | RobbinHood uses cmd.exe on the victim's computer. |
| T1070.005 Network Share Connection Removal |
MalwareRobbinHood | RobbinHood disconnects all network shares from the computer with the command |
| T1486 Data Encrypted for Impact |
MalwareRobbinHood | RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files. |
| T1489 Service Stop |
MalwareRobbinHood | RobbinHood stops 181 Windows services on the system before beginning the encryption process. |
| T1490 Inhibit System Recovery |
MalwareRobbinHood | RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily. |
| T1685 Disable or Modify Tools |
MalwareRobbinHood | RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.