HermeticWiper

威脅評分卡

威胁级别: 80 % (高的)
受感染的计算机: 11
初见: July 23, 2012
最后一次露面: November 14, 2025
受影响的操作系统: Windows

HermeticWiper 是一種極具破壞性的惡意軟件威脅,旨在使被破壞的計算機無法運行具體來說。該威脅針對烏克蘭的眾多組織,可能與俄羅斯入侵該國有關。根據幾家網絡安全供應商的結論,屬於不同行業組織(金融、航空、國防和 IT 服務)的數百台機器已經受到攻擊。受影響的計算機總數可能要高得多。

功能和攻擊細節

HermeticWiper 能夠破壞 Windows PC 的主引導記錄 (MBR),這是負責正確加載操作系統的關鍵組件。通過擦除它,惡意軟件會阻塞整個系統並阻止其啟動。據安全公司 SentinelOne 稱,該威脅使用的技術涉及利用免費 EaseUs Partition Master 應用程序的合法驅動程序,並導致系統硬盤驅動器損壞。至於威脅本身,它似乎是使用屬於一家名為“Hermetica Digital Ltd.”的公司的數字證書籤名的。位於塞浦路斯。

HermeticWiper 攻擊似乎是提前計劃好的,網絡犯罪分子在幾個月前就破壞了一些目標系統。在某些系統上,攻擊者還與 HermeticWiper 一起部署了勒索軟件威脅,但這一舉動很可能是為了掩蓋他們的真實意圖。

分析报告

一般信息

Family Name: Trojan.HermeticWiper
Signature status: Hash Mismatch

Known Samples

MD5: 382fc1a3c5225fceb672eea13f572a38
SHA1: d9a3596af0463797df4ff25b7999184946e3bfa2
SHA256: 2C10B2EC0B995B88C27D141D6F7B14D6B8177C52818687E4FF8E6ECF53ADF5BF
文件大小: 117.00 KB, 117000 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Digital Signatures

Signer Root Status
Hermetica Digital Ltd DigiCert EV Code Signing CA (SHA2) Hash Mismatch

Block Information

Total Blocks: 55
Potentially Malicious Blocks: 45
Whitelisted Blocks: 10
Unknown Blocks: 0

Visual Map

1 1 1 0 x 0 x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x 0 0 x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HermeticWiper.A

Files Modified

File Attributes
c: Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\system32\drivers\hzdr Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\system32\drivers\hzdr Generic Write,Read Attributes
c:\windows\system32\drivers\hzdr.sys Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value 数据 API Name
HKLM\system\controlset001\control\crashcontrol::crashdumpenabled RegNtPreCreateKey

Windows API Usage

Category API
Other Suspicious
  • AdjustTokenPrivileges
Service Control
  • OpenSCManager
  • OpenService

熱門

最受關注

加載中...