Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareFIVEHANDS | The FIVEHANDS payload is encrypted with AES-128. |
| T1059 Command and Scripting Interpreter |
MalwareFIVEHANDS | FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| T1083 File and Directory Discovery |
MalwareFIVEHANDS | FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions. |
| T1135 Network Share Discovery |
MalwareFIVEHANDS | FIVEHANDS can enumerate network shares and mounted drives on a network. |
| T1136.002 Domain Account |
ToolPsExec | PsExec has the ability to remotely create accounts on target systems. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareFIVEHANDS | FIVEHANDS has the ability to decrypt its payload prior to execution. |
| T1486 Data Encrypted for Impact |
MalwareFIVEHANDS | FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.