Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareWastedLocker | WastedLocker checks for specific registry keys related to the |
| T1027.013 Encrypted/Encoded File |
MalwareWastedLocker | The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file. |
| T1027.016 Junk Code Insertion |
MalwareWastedLocker | WastedLocker contains junk code to increase its entropy and hide the actual code. |
| T1059.003 Windows Command Shell |
MalwareWastedLocker | WastedLocker has used cmd to execute commands on the system. |
| T1083 File and Directory Discovery |
MalwareWastedLocker | WastedLocker can enumerate files and directories just prior to encryption. |
| T1106 Native API |
MalwareWastedLocker | WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload. |
| T1112 Modify Registry |
MalwareWastedLocker | WastedLocker can modify registry values within the |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWastedLocker | WastedLocker's custom cryptor, CryptOne, used an XOR based algorithm to decrypt the payload. |
| T1222.001 Windows Permissions |
MalwareWastedLocker | WastedLocker has a command to take ownership of a file and reset the ACL permissions using the |
| T1486 Data Encrypted for Impact |
MalwareWastedLocker | WastedLocker can encrypt data and leave a ransom note. |
| T1490 Inhibit System Recovery |
MalwareWastedLocker | WastedLocker can delete shadow volumes. |
| T1497.001 System Checks |
MalwareWastedLocker | WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique. |
| T1543.003 Windows Service |
MalwareWastedLocker | WastedLocker created and established a service that runs until the encryption process is complete. |
| T1548.002 Bypass User Account Control |
MalwareWastedLocker | WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later. |
| T1564.001 Hidden Files and Directories |
MalwareWastedLocker | WastedLocker has copied a random file from the Windows System32 folder to the |
| T1569.002 Service Execution |
MalwareWastedLocker | WastedLocker can execute itself as a service. |
| T1574.001 DLL |
MalwareWastedLocker | WastedLocker has performed DLL hijacking before execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.