Privilege Escalation
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1036 system_filename: Created a file named as a common system file
T1134 opens_process_token: Opens the access token associated with a process
Impact
T1486 ransomware_message: Ransomware indicators detected (possible ransom message creation)
T1486 ransomware_files: Ransomware indicators detected ProLock/Conti/GlobeImposter/BasilisqueLocker/CryptXXX/Shade/Maze/Medusa/Locky/Babuk (creates keys and the instruction on how to unlock the files)
T1486 ransomware_extensions: Ransomware(s) 7ev3n, Alcatraz, AlphaCrypt, AngryDuck, Apocalypse, Avaddon, Bart, CHIP, Cerber, Chimera, Clop, ComradeCircle, Conti, CryLocker, CrypVault, CryptXXX, CryptoMix, CryptoShield, Crysis, DXXD, Dharma, Domino, DummyLocker, Enigma, Exotic, FSociety, Fantom, Globe (aka Purga), Gremit, Hakbit, Herbst, Karma, KillerLocker, Kraken, LeChiffre, LegionLocker, LockLock, Lockbit, LockerGoga, Locky, Macop, Nuke, Odin, Phobos, Purge, QNAPCrypt, RadamantRansomwareKit, Razy, Rektlocker, Ryuk, Sage, Serpent, Shade, Teslacrypt, Thanos, ToxCrypt, Unlock92, VenusLocker, Vindows, Wannacry, WildFire indicators detected (specific extension is added to files)
T1486 ransomware_files_2: Ransomware(s) Apocalypse, BianLian, Conti, GlobeImposter, Karma, Locky, Lorenz, Maze, MedusaLocker, ProLock, RansomEXX, WaspLocker indicators detected (creates keys and the instruction on how to unlock the files)
Other
yara_rules: Static rules
ce_info: Diavol, BlackMatter, REvil note Configuration Data found
suncrypt: Detected SunCrypt ransomware
ransomware_blackcat: Detected BlackCat ransomware
blackmatter: Detected ransomware BlackMatter
ransomware_ragnarlocker: Detected RagnarLocker ransomware
ransomware_whiterabbit: Detected WhiteRabbit ransomware
ransomware_dharma: Detected Dharma ransomware
diavol: Detected Diavol ransomware
lorenz: Detected Lorenz ransomware
ransomware_avos: Detected Avos ransomware
hive: Detected Hive ransomware
revil: Ransomware REvil indicators detected
lockbit: Detected ransomware Lockbit
creates_exe: Creates executable files in the file system
creates_doc: Creates (office) documents in the file system
http_file_not_found: Attempts to download EXE or DLL file but receives HTML with an error
pe_overlay: PE file contains overlay