Short Name |
WORM:DISTTRACK-USER-AGENT |
---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
WORM |
Keywords |
Shamoon Malware Known Malicious User Agent DistTrack |
Release Date |
2012/08/20 |
Update Number |
2175 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects a known malicious user agent of DistTrack (aka "Shamoon") malware. Like other malware, it steals information, taking data from the 'Users', 'Documents and Settings', and 'System32/Drivers' and 'System32/Config' folders on Windows computers. One unusual characteristic, however, is that it can overwrite the master boot record (MBR) on infected machines, effectively rendering them useless.