ATT&CKReferencesSecure List Bad Rabbit

Secure List Bad Rabbit

Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareBad Rabbit

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.

T1053.005
Scheduled Task
MalwareBad Rabbit

Bad Rabbit’s infpub.dat file creates a scheduled task to launch a malicious executable.

T1057
Process Discovery
MalwareBad Rabbit

Bad Rabbit can enumerate all running processes to compare hashes.

T1110.003
Password Spraying
MalwareBad Rabbit

Bad Rabbit’s infpub.dat file uses NTLM login credentials to brute force Windows machines.

T1189
Drive-by Compromise
MalwareBad Rabbit

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.

T1204.002
Malicious File
MalwareBad Rabbit

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

T1210
Exploitation of Remote Services
MalwareBad Rabbit

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.

T1218.011
Rundll32
MalwareBad Rabbit

Bad Rabbit has used rundll32 to launch a malicious DLL as C:Windowsinfpub.dat.

T1486
Data Encrypted for Impact
MalwareBad Rabbit

Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048.

T1495
Firmware Corruption
MalwareBad Rabbit

Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up.

T1548.002
Bypass User Account Control
MalwareBad Rabbit

Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.