website statistics

Security firms have discovered a new malware which is being named 'Shamoon.' Shamoon steals data from a machine and then tries to render it unusable.
1 Star2 Stars3 Stars4 Stars5 Stars (Rate This)
Loading...

Most malware in recent days have been intended as tools to steal financial information or other important data. We saw that in the case of Flame and the more recent Gauss malware. Now, security firms have discovered yet another malware which is not as sophisticated but it tries to make your computer unusable. It is being touted as ‘Shamoon.’


According to Symantec, Shamoon “is a destructive malware that corrupts files on a compromised computer and overwrites the MBR (Master Boot Record) in an effort to render a computer unusable.” It’s rather intriguing for security researchers because most malware authors want to steal information, not to wreck the target machines.

Seculert, another security firm, provided a deeper insight into the workings of this malware. According to the firm, the first stage of the attack involves taking control of an internal machine and then hitching it up to an external Command-And-Control server. Once this is done, this infected machine is used to target other internal machines. In the second stage of the attack, Shamoon malware is released which then steals the data and overwrites MBR (Master Boot Record).

After looking into this new malware, Kaspersky noted, “Our opinion, based on researching several systems attacked by the original Wiper, is that it is not the same. The original ‘Wiper’ was using certain service names (‘RAHD…’) together with specific filenames for its drivers (‘%temp%\~dxxx.tmp’) which do not appear to be present in this malware. Additionally, the original Wiper was using a certain pattern to wipe disks which again is not used by this malware.”

Analysts believe that this malware is more the work of script kiddies who would create such a thing for the sheer fun of it. Any serious attacker wouldn’t want to make the target machine unusable.

Source: SecureList/ Seculert/ Symantec

Courtesy: PC Mag

Buy Cheapest Related Product From Amazon.com


D-Link Amplifi Cloud Router 5700 (DIR-865L)

You Can Also Build Mars Rover Curiosity Using LEGO Brick
You can also press the left/right arrow key on your keyboard to go to previous/next post
  On August 18, 2012(3 years, 9 months ago.)

You May Also Like:

What Do You Think?

Leave a Reply




Loading Facebook Comments ...

FTC Disclosure: Some of the links of this website are "affiliate links." This means if you click on the link and purchase the item, we will receive an affiliate commission.


Recent Search

Recent Tutorials

Have you forgot Apple ID password or having trouble signing in? Check out this tutorial to reset the password.
Even if iPhone is muted, still Siri's voice is loudly chime. Now you can change the setting to silence Siri using your iPhone's mute switch.
Check out how to teach Siri about nicknames and relationships of the important people in your life in order to make your life easier.
Has your iPhone suddenly turned black & white? Check out this tutorial to know possible reasons & how to fix iPhone screen with few taps.
Check out this tutorial to download FREE movies and TV Shows streaming Showbox app and install it on your Android smartphone or tablet.
Parental Controls allows you to put restrictions on apps or content that can or can not be used by anyone else on your Apple iPhone or iPad.
If you want to print from iPhone without using any computer, check this out to connect and print wirelessly right from the Apple device.
Using Siri, anyone can bypass the Passcode even if iPhone or iPad is locked. Check out this to know how you can disable Siri on lock screen.
Floatify will let you quick reply to the messages or emails through notification bar using your Android Lollipop or Marshmallow.
If you do not know to do face swap, check out this tutorial to learn how the new Snapchat face swapping feature actually works.
Close You Have To Login
User:
Pass:
Login With »Login With TwitterLogin With Facebook