DEADWOOD

S1134

Malware.View on attack.mitre.org

About this malware

DEADWOOD is wiper malware written in C++ using Boost libraries. DEADWOOD was first observed in an unattributed wiping event in Saudi Arabia in 2019, and has since been incorporated into Agrius operations.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1027.009
Embedded Payloads

DEADWOOD contains an embedded, AES-encrypted payload labeled METADATA that provides configuration information for follow-on execution.

T1027.013
Encrypted/Encoded File

DEADWOOD contains an embedded, AES-encrypted resource named METADATA that contains configuration information for follow-on execution.

T1036.004
Masquerade Task or Service

DEADWOOD will attempt to masquerade its service execution using benign-looking names such as ScDeviceEnums.

T1124
System Time Discovery

DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately.

T1140
Deobfuscate/Decode Files or Information

DEADWOOD XORs some strings within the binary using the value 0xD5, and deobfuscates these items at runtime.

T1485
Data Destruction

DEADWOOD overwrites files on victim systems with random data to effectively destroy them.

T1531
Account Access Removal

DEADWOOD changes the password for local and domain users via net.exe to a random 32 character string to prevent these accounts from logging on. Additionally, DEADWOOD will terminate the winlogon.exe process to prevent attempts to log on to the infected system.

T1561.001
Disk Content Wipe

DEADWOOD deletes files following overwriting them with random data.

T1561.002
Disk Structure Wipe

DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code IOCTL_DISK_DELETE_DRIVE_LAYOUT to ensure the MBR is removed from the drive.

T1569.002
Service Execution

DEADWOOD can be executed as a service using various names, such as ScDeviceEnums.

Groups that use it2

Campaigns0

None recorded.

References1

  1. SentinelOne Agrius 2021 Open source
    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.