Ransomware Analysis: Bad Rabbit
Executive Summary
This document presents a comprehensive analysis of the Bad Rabbit ransomware, detailing
its attack lifecycle and associated Tactics, Techniques, and Procedures (TTPs) as defined by
the MITRE ATT&CK framework. Bad Rabbit is known for its deceptive delivery methods,
leveraging drive-by compromises through a fake Adobe Flash installer. Upon execution, it
employs a unique mechanism of encrypting the Master Boot Record (MBR) and files,
causing significant disruption to infected systems. This ransomware differs from others like
NotPetya in its execution and impact, highlighting the evolving threat landscape and the
need for robust cybersecurity measures to mitigate such risks.
Bad Rabbit Ransomware
Stage Description and Behavior Associated TTPs (MITRE
ATT&CK References)
Initial Access Drive-by Compromise via T1190 - Exploit Public-
fake Adobe Flash installer; Facing Application, T1204 -
requires user execution User Execution
Execution Uses `[Link]` to T1085 - Rundll32, T1059 -
execute `[Link]`, which Command and Scripting
then executes `[Link]` Interpreter
Persistence Creates scheduled tasks; T1060 - Registry Run Keys /
modifies boot process to Startup Folder, T1053 -
load DiskCryptor driver Scheduled Task
`[Link]`
Privilege Escalation Attempts to bypass UAC; T1548 - Abuse Elevation
uses DiskCryptor for full Control Mechanism, T1068 -
disk encryption Exploitation for Privilege
Escalation
Defense Evasion Masquerades as legitimate T1027 - Obfuscated Files or
Flash installer; clears Information, T1070 -
Windows event logs; uses Indicator Removal on Host,
legitimate DiskCryptor for T1562.001 - Impair
encryption Defenses: Disable or Modify
Tools
Credential Access Uses Mimikatz-like T1003 - OS Credential
functionality to dump Dumping, T1056 - Input
credentials Capture
Discovery Enumerates SMB shares T1087 - Account Discovery,
and open ports; uses UPnP T1135 - Network Share
for system fingerprinting Discovery, T1046 - Network
Service Scanning
Lateral Movement Brute forces SMB logons; T1077 - Windows Admin
attempts remote service Shares, T1021 - Remote
execution with WMI Services, T1047 - Windows
Management
Instrumentation
Collection - -
Command and Control Uses a Tor hidden service T1071 - Application Layer
for command and control Protocol, T1090 - Proxy,
T1132 - Data Encoding
Exfiltration - -
Impact Encrypts files and disks; T1486 - Data Encrypted for
modifies MBR to display Impact, T1490 - Inhibit
ransom note System Recovery
References for Bad Rabbit:
MITRE ATT&CK: [Link]
Palo Alto Networks Unit 42: [Link]
ransomware/