Bad Rabbit
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1548 | .002 | Abuse Elevation Control Mechanism: Bypass User Account Control |
Bad Rabbit has attempted to bypass UAC and gain elevated administrative privileges.(Citation: Secure List Bad Rabbit) |
Enterprise | T1110 | .003 | Brute Force: Password Spraying |
Bad Rabbit’s |
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
Bad Rabbit has masqueraded as a Flash Player installer through the executable file |
Enterprise | T1003 | .001 | OS Credential Dumping: LSASS Memory |
Bad Rabbit has used Mimikatz to harvest credentials from the victim's machine.(Citation: ESET Bad Rabbit) |
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
Bad Rabbit’s |
Enterprise | T1218 | .011 | System Binary Proxy Execution: Rundll32 |
Bad Rabbit has used rundll32 to launch a malicious DLL as |
Enterprise | T1569 | .002 | System Services: Service Execution |
Bad Rabbit drops a file named |
Enterprise | T1204 | .002 | User Execution: Malicious File |
Bad Rabbit has been executed through user installation of an executable disguised as a flash installer.(Citation: ESET Bad Rabbit)(Citation: Secure List Bad Rabbit) |
Groups That Use This Software |
||
ID | Name | References |
---|---|---|
G0034 | Sandworm Team |
(Citation: Secureworks IRON VIKING ) |
References
- M.Léveille, M-E.. (2017, October 24). Bad Rabbit: Not‑Petya is back with improved ransomware. Retrieved January 28, 2021.
- Mamedov, O. Sinitsyn, F. Ivanov, A.. (2017, October 24). Bad Rabbit ransomware. Retrieved January 28, 2021.
- Slowik, J.. (2019, April 10). Implications of IT Ransomware for ICS Environments. Retrieved January 28, 2021.
- Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.