Lee, S.. (2019, May 14). JCry Ransomware. Retrieved June 18, 2019.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1059.001 PowerShell |
MalwareJCry | JCry has used PowerShell to execute payloads. |
| T1059.003 Windows Command Shell |
MalwareJCry | JCry has used |
| T1059.005 Visual Basic |
MalwareJCry | JCry has used VBS scripts. |
| T1204.002 Malicious File |
MalwareJCry | JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer. |
| T1486 Data Encrypted for Impact |
MalwareJCry | JCry has encrypted files and demanded Bitcoin to decrypt those files. |
| T1490 Inhibit System Recovery |
MalwareJCry | JCry has been observed deleting shadow copies to ensure that data cannot be restored easily. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareJCry | JCry has created payloads in the Startup directory to maintain persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.