Han, Karsten. (2019, June 4). Strange Bits: Sodinokibi Spam, CinaRAT, and Fake G DATA. Retrieved August 4, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareREvil | REvil has used encrypted strings and configuration files. |
| T1059.005 Visual Basic |
MalwareREvil | REvil has used obfuscated VBA macros for execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareREvil | REvil can decode encrypted strings to enable execution of commands and payloads. |
| T1204.002 Malicious File |
MalwareREvil | REvil has been executed via malicious MS Word e-mail attachments. |
| T1566.001 Spearphishing Attachment |
MalwareREvil | REvil has been distributed via malicious e-mail attachments including MS Word Documents. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.