ATT&CKReferencesMcafee Clop Aug 2019

Mcafee Clop Aug 2019

Mundo, A. (2019, August 1). Clop Ransomware. Retrieved May 10, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareClop

Clop has been packed to help avoid detection.

T1057
Process Discovery
MalwareClop

Clop can enumerate all processes on the victim's machine.

T1083
File and Directory Discovery
MalwareClop

Clop has searched folders and subfolders for files to encrypt.

T1106
Native API
MalwareClop

Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc().

T1135
Network Share Discovery
MalwareClop

Clop can enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwareClop

Clop has used a simple XOR operation to decrypt strings.

T1486
Data Encrypted for Impact
MalwareClop

Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files.

T1489
Service Stop
MalwareClop

Clop can kill several processes and services related to backups and security solutions.

T1490
Inhibit System Recovery
MalwareClop

Clop can delete the shadow volumes with vssadmin Delete Shadows /all /quiet and can use bcdedit to disable recovery options.

T1518.001
Security Software Discovery
MalwareClop

Clop can search for processes with antivirus and antimalware product names.

T1614.001
System Language Discovery
MalwareClop

Clop has checked the keyboard language using the GetKeyboardLayout() function to avoid installation on Russian-language or other Commonwealth of Independent States-language machines; it will also check the GetTextCharset function.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.