ATT&CKReferencesDFIR_Quantum_Ransomware

DFIR_Quantum_Ransomware

DFIR. (2022, April 25). Quantum Ransomware. Retrieved July 26, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareIcedID

IcedID used the `ipconfig /all` command and a batch script to gather network information.

T1053.005
Scheduled Task
MalwareIcedID

IcedID has created a scheduled task to establish persistence.

T1055.012
Process Hollowing
MalwareIcedID

IcedID can inject a Cobalt Strike beacon into cmd.exe via process hallowing.

T1071.001
Web Protocols
MalwareIcedID

IcedID has used HTTPS in communications with C2.

T1082
System Information Discovery
MalwareIcedID

IcedID has the ability to identify the computer name and OS version on a compromised host.

T1087.002
Domain Account
MalwareIcedID

IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect.

T1105
Ingress Tool Transfer
MalwareIcedID

IcedID has the ability to download additional modules and a configuration file from C2.

T1135
Network Share Discovery
MalwareIcedID

IcedID has used the `net view /all` command to show available shares.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1218.011
Rundll32
MalwareIcedID

IcedID has used rundll32.exe to execute the IcedID loader.

T1482
Domain Trust Discovery
MalwareIcedID

IcedID used Nltest during initial discovery.

T1518.001
Security Software Discovery
MalwareIcedID

IcedID can identify AV products on an infected host using the following command:
` WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get * /Format:List`.

T1614.001
System Language Discovery
MalwareIcedID

IcedID used the following command to check the country/language of the active console:
` cmd.exe /c chcp >&2`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.