ATT&CKReferencesTrend Micro KillDisk 1

Trend Micro KillDisk 1

Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
MalwareKillDisk

KillDisk uses VMProtect to make reverse engineering the malware more difficult.

T1106
Native API
MalwareKillDisk

KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine.

T1129
Shared Modules
MalwareKillDisk

KillDisk loads and executes functions from a DLL.

T1561.002
Disk Structure Wipe
MalwareKillDisk

KillDisk overwrites the first sector of the Master Boot Record with “0x00”.

T1680
Local Storage Discovery
MalwareKillDisk

KillDisk retrieves the hard disk name by calling the CreateFileA to \\.\PHYSICALDRIVE0 API.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.