ATT&CKReferencesESET Bad Rabbit

ESET Bad Rabbit

M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareBad Rabbit

Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location
MalwareBad Rabbit

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.

T1106
Native API
MalwareBad Rabbit

Bad Rabbit has used various Windows API calls.

T1135
Network Share Discovery
MalwareBad Rabbit

Bad Rabbit enumerates open SMB shares on internal victim networks.

T1189
Drive-by Compromise
MalwareBad Rabbit

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.

T1204.002
Malicious File
MalwareBad Rabbit

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.