ATT&CKReferencesIntel 471 REvil March 2020

Intel 471 REvil March 2020

Intel 471 Malware Intelligence team. (2020, March 31). REvil Ransomware-as-a-Service – An analysis of a ransomware affiliate operation. Retrieved August 4, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareREvil

REvil can enumerate active services.

T1027.011
Fileless Storage
MalwareREvil

REvil can save encryption parameters and system information in the Registry.

T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1059.001
PowerShell
MalwareREvil

REvil has used PowerShell to delete volume shadow copies and download files.

T1070.004
File Deletion
MalwareREvil

REvil can mark its binary code for deletion after reboot.

T1071.001
Web Protocols
MalwareREvil

REvil has used HTTP and HTTPS in communication with C2.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1083
File and Directory Discovery
MalwareREvil

REvil has the ability to identify specific files and directories that are not to be encrypted.

T1106
Native API
MalwareREvil

REvil can use Native API for execution and to retrieve active services.

T1112
Modify Registry
MalwareREvil

REvil can modify the Registry to save encryption parameters and system information.

T1140
Deobfuscate/Decode Files or Information
MalwareREvil

REvil can decode encrypted strings to enable execution of commands and payloads.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1489
Service Stop
MalwareREvil

REvil has the capability to stop services and kill processes.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.