Brandt, A., Mackenzie, P.. (2020, September 17). Maze Attackers Adopt Ragnar Locker Virtual Machine Technique. Retrieved October 9, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.004 Masquerade Task or Service |
MalwareMaze | Maze operators have created scheduled tasks masquerading as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update" designed to launch the ransomware. |
| T1047 Windows Management Instrumentation |
MalwareMaze | Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network. |
| T1053.005 Scheduled Task |
MalwareMaze | Maze has created scheduled tasks using name variants such as "Windows Update Security", "Windows Update Security Patches", and "Google Chrome Security Update", to launch Maze at a specific time. |
| T1055.001 Dynamic-link Library Injection |
MalwareMaze | Maze has injected the malware DLL into a target process. |
| T1059.003 Windows Command Shell |
MalwareMaze | The Maze encryption process has used batch scripts with various commands. |
| T1218.007 Msiexec |
MalwareMaze | Maze has delivered components for its ransomware attacks using MSI files, some of which have been executed from the command-line using |
| T1489 Service Stop |
MalwareMaze | Maze has stopped SQL services to ensure it can encrypt any database. |
| T1490 Inhibit System Recovery |
MalwareMaze | Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process. |
| T1529 System Shutdown/Reboot |
MalwareMaze | Maze has issued a shutdown command on a victim machine that, upon reboot, will run the ransomware within a VM. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareMaze | Maze has created a file named "startup_vrun.bat" in the Startup folder of a virtual machine to establish persistence. |
| T1564.006 Run Virtual Instance |
MalwareMaze | Maze operators have used VirtualBox and a Windows 7 virtual machine to run the ransomware; the virtual machine's configuration file mapped the shared network drives of the target company, presumably so Maze can encrypt files on the shared drives as well as the local machine. |
| T1685 Disable or Modify Tools |
MalwareMaze | Maze has disabled dynamic analysis and other security tools including IDA debugger, x32dbg, and OllyDbg. It has also disabled Windows Defender's Real-Time Monitoring feature and attempted to disable endpoint protection services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.