ATT&CKSoftwareBad Rabbit

Bad Rabbit

S0606

Malware.View on attack.mitre.org

About this malware

Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1003.001
LSASS Memory

Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.

T1036.005
Match Legitimate Resource Name or Location

Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.

T1053.005
Scheduled Task

Bad Rabbit’s infpub.dat file creates a scheduled task to launch a malicious executable.

T1057
Process Discovery

Bad Rabbit can enumerate all running processes to compare hashes.

T1106
Native API

Bad Rabbit has used various Windows API calls.

T1110.003
Password Spraying

Bad Rabbit’s infpub.dat file uses NTLM login credentials to brute force Windows machines.

T1135
Network Share Discovery

Bad Rabbit enumerates open SMB shares on internal victim networks.

T1189
Drive-by Compromise

Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a .js file.

T1204.002
Malicious File

Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.

T1210
Exploitation of Remote Services

Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks.

T1218.011
Rundll32

Bad Rabbit has used rundll32 to launch a malicious DLL as C:Windowsinfpub.dat.

T1486
Data Encrypted for Impact

Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048.

T1495
Firmware Corruption

Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up.

T1548.002
Bypass User Account Control

Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.

T1569.002
Service Execution

Bad Rabbit drops a file named infpub.datinto the Windows directory and is executed through SCManager and rundll.exe.

Groups that use it1

Campaigns0

None recorded.

References3

  1. Dragos Apr 2019 Open source
    Joe Slowik. (2019, April 10). Implications of IT Ransomware for ICS Environments. Retrieved October 27, 2019.
  2. ESET Bad Rabbit Open source
    M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.
  3. Secure List Bad Rabbit Open source
    Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.