mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
f7d92d59fa
- Updating capa detection in behaviors - Newsletter - Conti malware - pafish faq
1.6 KiB
1.6 KiB
| ID | F0014 |
| Objective(s) | Impact |
| Related ATT&CK Techniques | Disk Wipe (T1561.001) |
| Impact Type | Availability |
| Version | 3.0 |
| Created | 15 April 2021 |
| Last Modified | 13 September 2023 |
Disk Wipe
Malware may erase the content of storage devices. This behavior is different than Data Destruction (E1485) because sections of the disk are erased rather than individual files.
This description refines the ATT&CK Disk Wipe: Disk Content Wipe (T1561.001) sub-technique.
Use in Malware
| Name | Date | Method | Description |
|---|---|---|---|
| Shamoon | 2012 | -- | An overwrite component will overwrite the MBR so that the compromised computer can no longer start. [1] |
Detection
| Tool: capa | Mapping | APIs |
|---|---|---|
| overwrite Master Boot Record (MBR) | Disk Wipe (F0014) | kernel32.WriteFile |
References
[1] https://community.broadcom.com/symantecenterprise/communities/community-home/librarydocuments/viewdocument?DocumentKey=281521ea-2d18-4bf9-9e88-8b1dc41cfdb6&CommunityKey=1ecf5f55-9545-44d6-b0f4-4e4a7f5f5e68&tab=librarydocuments