Malware.View on attack.mitre.org
Clop is a ransomware family that was first observed in February 2019 and has been used against retail, transportation and logistics, education, manufacturing, engineering, automotive, energy, financial, aerospace, telecommunications, professional and legal services, healthcare, and high tech industries. Clop is a variant of the CryptoMix ransomware.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Clop has been packed to help avoid detection. |
| T1057 Process Discovery |
Clop can enumerate all processes on the victim's machine. |
| T1059.003 Windows Command Shell |
Clop can use cmd.exe to help execute commands on the system. |
| T1083 File and Directory Discovery |
Clop has searched folders and subfolders for files to encrypt. |
| T1106 Native API |
Clop has used built-in API functions such as WNetOpenEnumW(), WNetEnumResourceW(), WNetCloseEnum(), GetProcAddress(), and VirtualAlloc(). |
| T1112 Modify Registry |
Clop can make modifications to Registry keys. |
| T1135 Network Share Discovery |
Clop can enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
Clop has used a simple XOR operation to decrypt strings. |
| T1218.007 Msiexec |
Clop can use msiexec.exe to disable security tools on the system. |
| T1486 Data Encrypted for Impact |
Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files. |
| T1489 Service Stop |
Clop can kill several processes and services related to backups and security solutions. |
| T1490 Inhibit System Recovery |
Clop can delete the shadow volumes with |
| T1497.003 Time Based Checks |
Clop has used the |
| T1518.001 Security Software Discovery |
Clop can search for processes with antivirus and antimalware product names. |
| T1553.002 Code Signing |
Clop can use code signing to evade detection. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.