ATT&CKReferencesDFIR_Sodinokibi_Ransomware

DFIR_Sodinokibi_Ransomware

DFIR. (2021, March 29). Sodinokibi (aka REvil) Ransomware. Retrieved July 22, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareIcedID

IcedID has used WMI to execute binaries.

T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MalwareIcedID

IcedID has exfiltrated collected data via HTTPS.

T1053.005
Scheduled Task
MalwareIcedID

IcedID has created a scheduled task to establish persistence.

T1071.001
Web Protocols
MalwareIcedID

IcedID has used HTTPS in communications with C2.

T1204.002
Malicious File
MalwareIcedID

IcedID has been executed through Word and Excel files with malicious embedded macros and through ISO and LNK files that execute the malicious DLL.

T1482
Domain Trust Discovery
MalwareIcedID

IcedID used Nltest during initial discovery.

T1518.001
Security Software Discovery
MalwareIcedID

IcedID can identify AV products on an infected host using the following command:
` WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get * /Format:List`.

T1566.001
Spearphishing Attachment
MalwareIcedID

IcedID has been delivered via phishing e-mails with malicious attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.