FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareShamoon | Shamoon scans the C-class subnet of the IPs on the victim's interfaces. |
| T1021.002 SMB/Windows Admin Shares |
MalwareShamoon | Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware. |
| T1053.005 Scheduled Task |
MalwareShamoon | Shamoon copies an executable payload to the target system by using SMB/Windows Admin Shares and then scheduling an unnamed task to execute the malware. |
| T1078.002 Domain Accounts |
MalwareShamoon | If Shamoon cannot access shares using current privileges, it attempts access using hard coded, domain-specific credentials gathered earlier in the intrusion. |
| T1112 Modify Registry |
MalwareShamoon | Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting |
| T1485 Data Destruction |
MalwareShamoon | Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites. |
| T1561.002 Disk Structure Wipe |
MalwareShamoon | Shamoon has been seen overwriting features of disk structure such as the MBR. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.