ATT&CKReferencesPicus Sodinokibi January 2020

Picus Sodinokibi January 2020

Ozarslan, S. (2020, January 15). A Brief History of Sodinokibi. Retrieved August 5, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1036.005
Match Legitimate Resource Name or Location
MalwareREvil

REvil can mimic the names of known executables.

T1059.003
Windows Command Shell
MalwareREvil

REvil can use the Windows command line to delete volume shadow copies and disable recovery.

T1059.005
Visual Basic
MalwareREvil

REvil has used obfuscated VBA macros for execution.

T1105
Ingress Tool Transfer
MalwareREvil

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.

T1189
Drive-by Compromise
MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

T1204.002
Malicious File
MalwareREvil

REvil has been executed via malicious MS Word e-mail attachments.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1566.001
Spearphishing Attachment
MalwareREvil

REvil has been distributed via malicious e-mail attachments including MS Word Documents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.