ATT&CKReferencesMcAfee Sodinokibi October 2019

McAfee Sodinokibi October 2019

McAfee. (2019, October 2). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – What The Code Tells Us. Retrieved August 4, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
MalwareREvil

REvil can save encryption parameters and system information in the Registry.

T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1069.002
Domain Groups
MalwareREvil

REvil can identify the domain membership of a compromised host.

T1071.001
Web Protocols
MalwareREvil

REvil has used HTTP and HTTPS in communication with C2.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1083
File and Directory Discovery
MalwareREvil

REvil has the ability to identify specific files and directories that are not to be encrypted.

T1105
Ingress Tool Transfer
MalwareREvil

REvil can download a copy of itself from an attacker controlled IP address to the victim machine.

T1112
Modify Registry
MalwareREvil

REvil can modify the Registry to save encryption parameters and system information.

T1134.001
Token Impersonation/Theft
MalwareREvil

REvil can obtain the token from the user that launched the explorer.exe process to avoid affecting the desktop of the SYSTEM user.

T1140
Deobfuscate/Decode Files or Information
MalwareREvil

REvil can decode encrypted strings to enable execution of commands and payloads.

T1189
Drive-by Compromise
MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1566.001
Spearphishing Attachment
MalwareREvil

REvil has been distributed via malicious e-mail attachments including MS Word Documents.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.