Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts. |
| T1059.001 PowerShell |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts. |
| T1113 Screen Capture |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines. |
| T1219 Remote Access Tools |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil. |
| T1486 Data Encrypted for Impact |
MalwareREvil | REvil can encrypt files on victim systems and demands a ransom to decrypt the files. |
| T1490 Inhibit System Recovery |
MalwareREvil | REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.