ATT&CKReferencesSophos SamSam Apr 2018

Sophos SamSam Apr 2018

Palotay, D. and Mackenzie, P. (2018, April). SamSam Ransomware Chooses Its Targets Carefully. Retrieved April 15, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareSamSam

SamSam has been seen using AES or DES to encrypt payloads and payload components.

T1027.016
Junk Code Insertion
MalwareSamSam

SamSam has used garbage code to pad some of its malware components.

T1059.003
Windows Command Shell
MalwareSamSam

SamSam uses custom batch scripts to execute some of its components.

T1070.004
File Deletion
MalwareSamSam

SamSam has been seen deleting its own files and payloads to make analysis of the attack more difficult.

T1486
Data Encrypted for Impact
MalwareSamSam

SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.