Malware.View on attack.mitre.org
Bad Rabbit is a self-propagating ransomware that affected the Ukrainian transportation sector in 2017. Bad Rabbit has also targeted organizations and consumers in Russia.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine. |
| T1036.005 Match Legitimate Resource Name or Location |
Bad Rabbit has masqueraded as a Flash Player installer through the executable file |
| T1053.005 Scheduled Task |
Bad Rabbit’s |
| T1057 Process Discovery |
Bad Rabbit can enumerate all running processes to compare hashes. |
| T1106 Native API |
Bad Rabbit has used various Windows API calls. |
| T1110.003 Password Spraying |
Bad Rabbit’s |
| T1135 Network Share Discovery |
Bad Rabbit enumerates open SMB shares on internal victim networks. |
| T1189 Drive-by Compromise |
Bad Rabbit spread through watering holes on popular sites by injecting JavaScript into the HTML body or a |
| T1204.002 Malicious File |
Bad Rabbit has been executed through user installation of an executable disguised as a flash installer. |
| T1210 Exploitation of Remote Services |
Bad Rabbit used the EternalRomance SMB exploit to spread through victim networks. |
| T1218.011 Rundll32 |
Bad Rabbit has used rundll32 to launch a malicious DLL as |
| T1486 Data Encrypted for Impact |
Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048. |
| T1495 Firmware Corruption |
Bad Rabbit has used an executable that installs a modified bootloader to prevent normal boot-up. |
| T1548.002 Bypass User Account Control |
Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges. |
| T1569.002 Service Execution |
Bad Rabbit drops a file named |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.