Mundo, A. et al. (2021, February). Technical Analysis of Babuk Ransomware. Retrieved August 11, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareBabuk | Babuk can enumerate all services running on a compromised host. |
| T1027.002 Software Packing |
MalwareBabuk | Versions of Babuk have been packed. |
| T1049 System Network Connections Discovery |
MalwareBabuk | Babuk can use “WNetOpenEnumW” and “WNetEnumResourceW” to enumerate files in network resources for encryption. |
| T1057 Process Discovery |
MalwareBabuk | Babuk has the ability to check running processes on a targeted system. |
| T1059.003 Windows Command Shell |
MalwareBabuk | Babuk has the ability to use the command line to control execution on compromised hosts. |
| T1083 File and Directory Discovery |
MalwareBabuk | Babuk has the ability to enumerate files on a targeted system. |
| T1106 Native API |
MalwareBabuk | Babuk can use multiple Windows API calls for actions on compromised hosts including discovery and execution. |
| T1486 Data Encrypted for Impact |
MalwareBabuk | Babuk can use ChaCha8 and ECDH to encrypt data. |
| T1489 Service Stop |
MalwareBabuk | Babuk can stop specific services related to backups. |
| T1490 Inhibit System Recovery |
MalwareBabuk | Babuk has the ability to delete shadow volumes using |
| T1680 Local Storage Discovery |
MalwareBabuk | Babuk can enumerate disk volumes, get disk information, and query service status. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.