Mundo, A., Roccia, T., Saavedra-Morales, J., Beek, C.. (2018, December 14). Shamoon Returns to Wipe Systems in Middle East, Europe . Retrieved May 29, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareShamoon | Shamoon obtains the target's IP address and local network segment. |
| T1036.004 Masquerade Task or Service |
MalwareShamoon | Shamoon creates a new service named “ntssrv” that attempts to appear legitimate; the service's display name is “Microsoft Network Realtime Inspection Service” and its description is “Helps guard against time change attempts targeting known and newly discovered vulnerabilities in network time protocols.” Newer versions create the "MaintenaceSrv" service, which misspells the word "maintenance." |
| T1070.006 Timestomp |
MalwareShamoon | Shamoon can change the modified time for files to evade forensic detection. |
| T1112 Modify Registry |
MalwareShamoon | Once Shamoon has access to a network share, it enables the RemoteRegistry service on the target system. It will then connect to the system with RegConnectRegistryW and modify the Registry to disable UAC remote restrictions by setting |
| T1134.001 Token Impersonation/Theft |
MalwareShamoon | Shamoon can impersonate tokens using |
| T1485 Data Destruction |
MalwareShamoon | Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites. |
| T1529 System Shutdown/Reboot |
MalwareShamoon | Shamoon will reboot the infected system once the wiping functionality has been completed. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.