ATT&CKReferencesCarbonBlack RobbinHood May 2019

CarbonBlack RobbinHood May 2019

Lee, S. (2019, May 17). CB TAU Threat Intelligence Notification: RobbinHood Ransomware Stops 181 Windows Services Before Encryption. Retrieved July 29, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.003
Windows Command Shell
MalwareRobbinHood

RobbinHood uses cmd.exe on the victim's computer.

T1070.005
Network Share Connection Removal
MalwareRobbinHood

RobbinHood disconnects all network shares from the computer with the command net use * /DELETE /Y.

T1486
Data Encrypted for Impact
MalwareRobbinHood

RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files.

T1489
Service Stop
MalwareRobbinHood

RobbinHood stops 181 Windows services on the system before beginning the encryption process.

T1490
Inhibit System Recovery
MalwareRobbinHood

RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily.

T1685
Disable or Modify Tools
MalwareRobbinHood

RobbinHood will search for Windows services that are associated with antivirus software on the system and kill the process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.