timb-machine / timb-machine/linux-malware

[Intel]: https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/

Open
#119 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

ignore:tag:T1021.002 ignore:tag:T1027.002 ignore:tag:T1037 ignore:tag:T1048 ignore:tag:T1053.006 ignore:tag:T1057 ignore:tag:T1070.002 ignore:tag:T1070.004 ignore:tag:T1071.001 ignore:tag:T1491 ignore:tag:T1543.002 ignore:tag:T1546.004 ignore:tag:T1567 ignore:tag:T1573 ignore:tag:T1590 missing:tactics missing:tag:T1007 missing:tag:T1053.003
Dominant language
HTML
Stars
1.2k
Forks
95
PR merge metrics
No merged PRs in 30d

Description

Area

Malware reports

Parent threat

Impact

Finding

https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/

Industry reference

attack:T1485:Data Destruction
attack:T1053.003:Cron
attack:T1016:System Network Configuration Discovery
attack:T1110.003:Password Spraying
attack:T1490:Inhibit System Recovery
attack:T1027:Obfuscated Files or Information
attack:T1561.001:Disk Content Wipe
attack:T1529:System Shutdown/Reboot
attack:T1007:System Service Discovery
attack:T1021.004:SSH

Malware reference

Industroyer
ORCSHRED
SOLOSHRED
AWFULSHRED

Actor reference

Sandworm

Component

Linux, Solaris, Industrial

Scenario

No response

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked ESET report and inspect the repository's existing malware-report entries to identify how findings are recorded. Confirm how the Industroyer, ORCSHRED, SOLOSHRED, AWFULSHRED, Sandworm, ATT&CK techniques, and Linux/Solaris/Industrial details should be represented; done means the report is added consistently with the project's existing data.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
operating-systems, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.