.. /mv
Star

Replace File

Used for moving or renaming files/folders within a file system.


Paths:

Resources:
Acknowledgements:

Replace File

  1. Renames the Message Of The Day file.

    mv /etc/motd /etc/motd1
    Use case
    An adversary renames the current motd file on an ESXi host and copies a custom version to its location. This usually contain the ransom notification.
    Privileges required
    Administrator
    Operating systems
    ESXi
    ATT&CK® technique
    T1491

    Tags
    E-Crime: Nevada
    Nevada Ransomware operates via an an affiliate program and has been reported to have carried out a campaign targeting any ESXi machine that is exposed to the internet