ai ttp extraction
ID: 2e5589ba-4fa9-46c2-a1ab-9bfa2e353c8c
STIX ID: report--2e5589ba-4fa9-46c2-a1ab-9bfa2e353c8c
Threat Score
50/100
The report highlights a technique employed by the REvil ransomware group, which involves using Windows Management Instrumentation (WMI) to execute malicious commands. This method is part of their strategy to reference a retrieved Portable Executable (PE) file through a path modification, showcasing their sophisticated approach to deploying ransomware.
