Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

WORM:DISTTRACK-CNC

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

WORM

Keywords

Shamoon Malware Known Malicious User Agent DistTrack

Release Date

2012/08/20

Update Number

2175

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

WORM: DistTrack Command and Control Traffic


This signature detects the Command and Control traffic for the DistTrack (aka "Shamoon") malware. The source IP host is infected and should be removed from the network for analysis. Like other malware, it steals information, taking data from the 'Users', 'Documents and Settings', and 'System32/Drivers' and 'System32/Config' folders on Windows computers. One unusual characteristic, however, is that it can overwrite the master boot record (MBR) on infected machines, effectively rendering them useless.

References

  • URL: http://www.zdnet.com/shamoon-malware-infects-computers-steals-data-then-wipes-them-7000002807/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out