Mundo, A. (2019, August 1). Clop Ransomware. Retrieved May 10, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareClop | Clop has been packed to help avoid detection. |
| T1057 Process Discovery |
MalwareClop | Clop can enumerate all processes on the victim's machine. |
| T1083 File and Directory Discovery |
MalwareClop | Clop has searched folders and subfolders for files to encrypt. |
| T1106 Native API |
MalwareClop | Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc(). |
| T1135 Network Share Discovery |
MalwareClop | Clop can enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareClop | Clop has used a simple XOR operation to decrypt strings. |
| T1486 Data Encrypted for Impact |
MalwareClop | Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files. |
| T1489 Service Stop |
MalwareClop | Clop can kill several processes and services related to backups and security solutions. |
| T1490 Inhibit System Recovery |
MalwareClop | Clop can delete the shadow volumes with |
| T1518.001 Security Software Discovery |
MalwareClop | Clop can search for processes with antivirus and antimalware product names. |
| T1614.001 System Language Discovery |
MalwareClop | Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.