Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwareShamoon | Shamoon queries several Registry keys to identify hard disk partitions to overwrite. |
| T1016 System Network Configuration Discovery |
MalwareShamoon | Shamoon obtains the target's IP address and local network segment. |
| T1027 Obfuscated Files or Information |
MalwareShamoon | Shamoon contains base64-encoded strings. |
| T1036.004 Masquerade Task or Service |
MalwareShamoon | Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance." |
| T1053.005 Scheduled Task |
MalwareShamoon | Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware. |
| T1071.001 Web Protocols |
MalwareShamoon | Shamoon has used HTTP for C2. |
| T1082 System Information Discovery |
MalwareShamoon | Shamoon obtains the victim's operating system version and keyboard layout and sends the information to the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareShamoon | Shamoon can download an executable to run on the victim. |
| T1112 Modify Registry |
MalwareShamoon | Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting |
| T1124 System Time Discovery |
MalwareShamoon | Shamoon obtains the system time and will only activate if it is greater than a preset date. |
| T1485 Data Destruction |
ToolRawDisk | RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data. |
| T1485 Data Destruction |
MalwareShamoon | Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites. |
| T1486 Data Encrypted for Impact |
MalwareShamoon | Shamoon has an operational mode for encrypting data instead of overwriting it. |
| T1543.003 Windows Service |
MalwareShamoon | Shamoon creates a new service named “ntssrv” to execute the payload. Newer versions create the "MaintenaceSrv" and "hdv_725x" services. |
| T1548.002 Bypass User Account Control |
MalwareShamoon | Shamoon attempts to disable UAC remote restrictions by modifying the Registry. |
| T1561.002 Disk Structure Wipe |
ToolRawDisk | RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions. |
| T1561.002 Disk Structure Wipe |
MalwareShamoon | Shamoon has been seen overwriting features of disk structure such as the MBR. |
| T1569.002 Service Execution |
MalwareShamoon | Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec. |
| T1570 Lateral Tool Transfer |
MalwareShamoon | Shamoon attempts to copy itself to remote machines on the network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.