MultiLayer Wiper
Techniques Used |
||||
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs.(Citation: Unit42 Agrius 2023) |
Enterprise | T1565 | .001 | Data Manipulation: Stored Data Manipulation |
MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult.(Citation: Unit42 Agrius 2023) |
Enterprise | T1561 | .002 | Disk Wipe: Disk Structure Wipe |
MultiLayer Wiper opens a handle to |
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies.(Citation: Unit42 Agrius 2023) |
Enterprise | T1070 | .001 | Indicator Removal: Clear Windows Event Logs |
MultiLayer Wiper removes Windows event logs during execution.(Citation: Unit42 Agrius 2023) |
.004 | Indicator Removal: File Deletion |
MultiLayer Wiper uses a batch file, |
||
.006 | Indicator Removal: Timestomp |
MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems.(Citation: Unit42 Agrius 2023) |
||
Enterprise | T1027 | .009 | Obfuscated Files or Information: Embedded Payloads |
MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution.(Citation: Unit42 Agrius 2023) |
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
MultiLayer Wiper creates a malicious scheduled task that launches a batch file to remove Windows Event Logs.(Citation: Unit42 Agrius 2023) |
Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.