Short Name |
WORM:DISTTRACK-CNC |
---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
WORM |
Keywords |
Shamoon Malware Known Malicious User Agent DistTrack |
Release Date |
2012/08/20 |
Update Number |
2175 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects the Command and Control traffic for the DistTrack (aka "Shamoon") malware. The source IP host is infected and should be removed from the network for analysis. Like other malware, it steals information, taking data from the 'Users', 'Documents and Settings', and 'System32/Drivers' and 'System32/Config' folders on Windows computers. One unusual characteristic, however, is that it can overwrite the master boot record (MBR) on infected machines, effectively rendering them useless.