Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak. Retrieved October 30, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
ToolAdFind | AdFind can extract subnet information from Active Directory. |
| T1018 Remote System Discovery |
ToolAdFind | AdFind has the ability to query Active Directory for computers. |
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1069.002 Domain Groups |
ToolAdFind | AdFind can enumerate domain groups. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
| T1482 Domain Trust Discovery |
ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
| T1566.001 Spearphishing Attachment |
GroupWizard Spider | Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.