ATT&CKReferencesMcAfee Shamoon December 2018

McAfee Shamoon December 2018

Mundo, A., Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 14). Shamoon Returns to Wipe Systems in Middle East, Europe . Retrieved May 29, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareShamoon

Shamoon obtains the target's IP address and local network segment.

T1036.004
Masquerade Task or Service
MalwareShamoon

Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance."

T1070.006
Timestomp
MalwareShamoon

Shamoon can change the modified time for files to evade forensic detection.

T1112
Modify Registry
MalwareShamoon

Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy to 1.

T1134.001
Token Impersonation/Theft
MalwareShamoon

Shamoon can impersonate tokens using LogonUser, ImpersonateLoggedOnUser, and ImpersonateNamedPipeClient.

T1485
Data Destruction
MalwareShamoon

Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites.

T1529
System Shutdown/Reboot
MalwareShamoon

Shamoon will reboot the infected system once the wiping functionality has been completed.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.