logo

ai ttp extraction

ID: 2e5589ba-4fa9-46c2-a1ab-9bfa2e353c8c

STIX ID: report--2e5589ba-4fa9-46c2-a1ab-9bfa2e353c8c

Threat Score

50/100

Uploaded: 2025-10-17

Created by: team 7

TLP:GREEN
...
...
The report highlights a technique employed by the REvil ransomware group, which involves using Windows Management Instrumentation (WMI) to execute malicious commands. This method is part of their strategy to reference a retrieved Portable Executable (PE) file through a path modification, showcasing their sophisticated approach to deploying ransomware.