Avaddon
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1548 | .002 | Abuse Elevation Control Mechanism: Bypass User Account Control |
Avaddon bypasses UAC using the CMSTPLUA COM interface.(Citation: Arxiv Avaddon Feb 2021) |
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
Avaddon uses registry run keys for persistence.(Citation: Arxiv Avaddon Feb 2021) |
Enterprise | T1059 | .007 | Command and Scripting Interpreter: JavaScript |
Avaddon has been executed through a malicious JScript downloader.(Citation: Hornet Security Avaddon June 2020)(Citation: Awake Security Avaddon) |
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
Avaddon looks for and attempts to stop anti-malware solutions.(Citation: Arxiv Avaddon Feb 2021) |
Enterprise | T1614 | .001 | System Location Discovery: System Language Discovery |
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities.(Citation: Arxiv Avaddon Feb 2021) |
References
- Gahlot, A. (n.d.). Threat Hunting for Avaddon Ransomware. Retrieved August 19, 2021.
- Yuste, J. Pastrana, S. (2021, February 9). Avaddon ransomware: an in-depth analysis and decryption of infected systems. Retrieved August 19, 2021.
- Security Lab. (2020, June 5). Avaddon: From seeking affiliates to in-the-wild in 2 days. Retrieved August 19, 2021.
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.