Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareREvil | REvil has used encrypted strings and configuration files. |
| T1047 Windows Management Instrumentation |
MalwareREvil | REvil can use WMI to monitor for and kill specific processes listed in its configuration file. |
| T1059.001 PowerShell |
MalwareREvil | REvil has used PowerShell to delete volume shadow copies and download files. |
| T1082 System Information Discovery |
MalwareREvil | REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
| T1680 Local Storage Discovery |
MalwareREvil | REvil can identify system drive information on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.