Mamedov, O, et al. (2019, July 3). Sodin ransomware exploits Windows vulnerability and processor architecture. Retrieved August 4, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1069.002 Domain Groups |
MalwareREvil | REvil can identify the domain membership of a compromised host. |
| T1082 System Information Discovery |
MalwareREvil | REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
| T1083 File and Directory Discovery |
MalwareREvil | REvil has the ability to identify specific files and directories that are not to be encrypted. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareREvil | REvil can decode encrypted strings to enable execution of commands and payloads. |
| T1485 Data Destruction |
MalwareREvil | REvil has the capability to destroy files and folders. |
| T1486 Data Encrypted for Impact |
MalwareREvil | REvil can encrypt files on victim systems and demands a ransom to decrypt the files. |
| T1490 Inhibit System Recovery |
MalwareREvil | REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features. |
| T1573.002 Asymmetric Cryptography |
MalwareREvil | REvil has encrypted C2 communications with the ECIES algorithm. |
| T1614.001 System Language Discovery |
MalwareREvil | REvil can check the system language using |
| T1680 Local Storage Discovery |
MalwareREvil | REvil can identify system drive information on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.