Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareREvil | REvil has used encrypted strings and configuration files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareREvil | REvil can mimic the names of known executables. |
| T1059.003 Windows Command Shell |
MalwareREvil | REvil can use the Windows command line to delete volume shadow copies and disable recovery. |
| T1059.005 Visual Basic |
MalwareREvil | REvil has used obfuscated VBA macros for execution. |
| T1105 Ingress Tool Transfer |
MalwareREvil | REvil can download a copy of itself from an attacker controlled IP address to the victim machine. |
| T1189 Drive-by Compromise |
MalwareREvil | REvil has infected victim machines through compromised websites and exploit kits. |
| T1204.002 Malicious File |
MalwareREvil | REvil has been executed via malicious MS Word e-mail attachments. |
| T1485 Data Destruction |
MalwareREvil | REvil has the capability to destroy files and folders. |
| T1486 Data Encrypted for Impact |
MalwareREvil | REvil can encrypt files on victim systems and demands a ransom to decrypt the files. |
| T1490 Inhibit System Recovery |
MalwareREvil | REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features. |
| T1566.001 Spearphishing Attachment |
MalwareREvil | REvil has been distributed via malicious e-mail attachments including MS Word Documents. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.