DFIR. (2021, March 29). Sodinokibi (aka REvil) Ransomware. Retrieved July 22, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareIcedID | IcedID has used WMI to execute binaries. |
| T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
MalwareIcedID | IcedID has exfiltrated collected data via HTTPS. |
| T1053.005 Scheduled Task |
MalwareIcedID | IcedID has created a scheduled task to establish persistence. |
| T1071.001 Web Protocols |
MalwareIcedID | IcedID has used HTTPS in communications with C2. |
| T1204.002 Malicious File |
MalwareIcedID | IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL. |
| T1482 Domain Trust Discovery |
MalwareIcedID | |
| T1518.001 Security Software Discovery |
MalwareIcedID | IcedID can identify AV products on an infected host using the following command: |
| T1566.001 Spearphishing Attachment |
MalwareIcedID | IcedID has been delivered via phishing e-mails with malicious attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.