ATT&CKReferencesDFIR Ryuk's Return October 2020

DFIR Ryuk's Return October 2020

The DFIR Report. (2020, October 8). Ryuk’s Return. Retrieved October 9, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1021.002
SMB/Windows Admin Shares
GroupWizard Spider

Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.

T1027.010
Command Obfuscation
GroupWizard Spider

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.

T1047
Windows Management Instrumentation
MalwareBazar

Bazar can execute a WMI query to gather information about the installed antivirus engine.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupWizard Spider

Wizard Spider has exfiltrated victim information using FTP.

T1059.003
Windows Command Shell
GroupWizard Spider

Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.

T1082
System Information Discovery
GroupWizard Spider

Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory.

T1087.002
Domain Account
MalwareBazar

Bazar has the ability to identify domain administrator accounts.

T1087.002
Domain Account
GroupWizard Spider

Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.

T1210
Exploitation of Remote Services
GroupWizard Spider

Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.

T1482
Domain Trust Discovery
ToolRubeus

Rubeus can gather information about domain trusts.

T1489
Service Stop
GroupWizard Spider

Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.

T1518.001
Security Software Discovery
GroupWizard Spider

Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1558.004
AS-REP Roasting
ToolRubeus

Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.