ATT&CKReferencesKaspersky Sodin July 2019

Kaspersky Sodin July 2019

Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1069.002
Domain Groups
MalwareREvil

REvil can identify the domain membership of a compromised host.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1083
File and Directory Discovery
MalwareREvil

REvil has the ability to identify specific files and directories that are not to be encrypted.

T1140
Deobfuscate/Decode Files or Information
MalwareREvil

REvil can decode encrypted strings to enable execution of commands and payloads.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1573.002
Asymmetric Cryptography
MalwareREvil

REvil has encrypted C2 communications with the ECIES algorithm.

T1614.001
System Language Discovery
MalwareREvil

REvil can check the system language using GetUserDefaultUILanguage and GetSystemDefaultUILanguage. If the language is found in the list, the process terminates.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.