ATT&CKReferencesKaspersky StoneDrill 2017

Kaspersky StoneDrill 2017

Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareStoneDrill

StoneDrill has looked in the registry to find the default browser path.

T1027.013
Encrypted/Encoded File
MalwareStoneDrill

StoneDrill has obfuscated its module with an alphabet-based table or XOR encryption.

T1047
Windows Management Instrumentation
MalwareStoneDrill

StoneDrill has used the WMI command-line (WMIC) utility to run tasks.

T1055
Process Injection
MalwareStoneDrill

StoneDrill has relied on injecting its payload directly into the process memory of the victim's preferred browser.

T1059.005
Visual Basic
MalwareStoneDrill

StoneDrill has several VBS scripts used throughout the malware's lifecycle.

T1070.004
File Deletion
MalwareStoneDrill

StoneDrill has been observed deleting the temporary files once they fulfill their task.

T1082
System Information Discovery
MalwareStoneDrill

StoneDrill has the capability to discover the system OS, Windows version, architecture and environment.

T1105
Ingress Tool Transfer
MalwareStoneDrill

StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.

T1113
Screen Capture
MalwareStoneDrill

StoneDrill can take screenshots.

T1124
System Time Discovery
MalwareStoneDrill

StoneDrill can obtain the current date and time of the victim machine.

T1485
Data Destruction
MalwareStoneDrill

StoneDrill has a disk wiper module that targets files other than those in the Windows directory.

T1497
Virtualization/Sandbox Evasion
MalwareStoneDrill

StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes.

T1518.001
Security Software Discovery
MalwareStoneDrill

StoneDrill can check for antivirus and antimalware programs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.