Cybereason Nocturnus. (2020, December 23). Cybereason vs. Clop Ransomware. Retrieved May 11, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareClop | Clop has been packed to help avoid detection. |
| T1059.003 Windows Command Shell |
MalwareClop | Clop can use cmd.exe to help execute commands on the system. |
| T1106 Native API |
MalwareClop | Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc(). |
| T1112 Modify Registry |
MalwareClop | Clop can make modifications to Registry keys. |
| T1218.007 Msiexec |
MalwareClop | Clop can use msiexec.exe to disable security tools on the system. |
| T1486 Data Encrypted for Impact |
MalwareClop | Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files. |
| T1518.001 Security Software Discovery |
MalwareClop | Clop can search for processes with antivirus and antimalware product names. |
| T1685 Disable or Modify Tools |
MalwareClop | Clop can uninstall or disable security products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.