A disk wiping Shamoon malware performing destructive attack sample using an image of a burning US Dollar.
This malware was uploaded in virus total from France on December 23, 2018, and it signed with a digital certificate from Baidu.
Previous Attack destructive malware dubbed Shamoon V3 targeting European oil and gas company in the
Shamoon destructive wiper using an image that burning American flag and the drowned Syrian refugee and child as part of targeted attacks.
It using powerful obfuscation technique utilizes the commercial packing tool Enigma version 4 .
“As observed in previous Shamoon samples the internal file name invokes a known PC tool, likely as a lure to allay initial user suspicion.”
Shamoon Malware Distribution
In order to Shamoon malware look like an legitimate software, its distributed with the malicious file name as “Baidu PC Faster” and uses the description “Baidu WiFi Hotspot Setup
Detailed research reveals that its contain some similarities with
Shamoon V2 malware especially a resource called “GRANT” which is an indication of the malware complied based on the codebase that used by the
Also, some of the other discovered sample timestamps show that it was created, 2011.
According to
This possibility is highlighted by the use of US currency in the political image that accompanies the destructive malware.
“
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.