Skip to main content

New Shamoon malware variant in the wild

posted onSeptember 5, 2012
by l33tdawg

Symantec has released a new warning after finding that an updated variant of malware Shamoon is in the wild. The new version -- detected by the company as W32.Disttrack -- wipes and destroys files as well as the master boot record (MBR) and changing the active partitions of an infected machine.

Instead of the previous version's methods of overwriting through 192KB blocks complete with a burning U.S. flag, the new variant uses the same size of block with randomly generated data. The wiping date is read from a .pnf file created on the system. Symantec says that the date is checked periodically, and then executes the wiper.
symantec sharnoon malware

Scanning through a targeted list of 'priority' files, the malware seeks out a target through attempting to open and close the following files to determine access rights:

    \\[TARGET IP]\ADMIN$\system32\csrss.exe \\[TARGET IP]\C$\WINDOWS\system32\csrss.exe \\[TARGET IP]\D$\WINDOWS\system32\csrss.exe \\[TARGET IP]\E$\WINDOWS\system32\csrss.exe

Source

Tags

Symantec Industry News Viruses & Malware

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th