ATT&CKReferencesCybereason Clop Dec 2020

Cybereason Clop Dec 2020

Cybereason Nocturnus. (2020, December 23). Cybereason vs. Clop Ransomware. Retrieved May 11, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareClop

Clop has been packed to help avoid detection.

T1059.003
Windows Command Shell
MalwareClop

Clop can use cmd.exe to help execute commands on the system.

T1106
Native API
MalwareClop

Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc().

T1112
Modify Registry
MalwareClop

Clop can make modifications to Registry keys.

T1218.007
Msiexec
MalwareClop

Clop can use msiexec.exe to disable security tools on the system.

T1486
Data Encrypted for Impact
MalwareClop

Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files.

T1518.001
Security Software Discovery
MalwareClop

Clop can search for processes with antivirus and antimalware product names.

T1685
Disable or Modify Tools
MalwareClop

Clop can uninstall or disable security products.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.