Třída: Trojan-Ransom
Tento typ trojského koně modifikuje data na počítači poškozeného, takže oběť již nemůže používat data nebo zabraňuje správnému fungování počítače. Jakmile budou data "rukojmím" (zablokována nebo zašifrována), uživatel obdrží požadavek na výkupné.Požadavek výkupného žádá oběť, aby poslala škodlivé uživatelské peníze; po obdržení tohoto kroku pošle počítačový zločinec poškozenému program obnovení dat nebo obnovení výkonu počítače.
Platfoma: Win32
Win32 je rozhraní API v operačních systémech Windows NT (Windows XP, Windows 7 atd.), Které podporují provádění 32bitových aplikací. Jedna z nejrozšířenějších programovacích platforem na světě.Family: Trojan-Ransom.Win32.Gen
No family descriptionExamples
78CF090F00D513978C664ABF2C85EDD5Tactics and Techniques: Mitre*
TA0011
Command and Control
The adversary is trying to communicate with compromised systems to control them. Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim's network structure and defenses.
T1102
Web Service
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.