This malware was uploaded in virus total from France on December 23, 2018, and it signed with a digital certificate from Baidu.
Previous Attack destructive malware dubbed Shamoon V3 targeting European oil and gas company in the
Shamoon destructive wiper using an image that burning American flag and the drowned Syrian refugee and child as part of targeted attacks.
It using powerful obfuscation technique utilizes the commercial packing tool Enigma version 4 .
“As observed in previous Shamoon samples the internal file name invokes a known PC tool, likely as a lure to allay initial user suspicion.”
Shamoon Malware Distribution
In order to Shamoon malware look like an legitimate software, its distributed with the malicious file name as “Baidu PC Faster” and uses the description “Baidu WiFi Hotspot Setup
Detailed research reveals that its contain some similarities with
Shamoon V2 malware especially a resource called “GRANT” which is an indication of the malware complied based on the codebase that used by the
Also, some of the other discovered sample timestamps show that it was created, 2011.
This possibility is highlighted by the use of US currency in the political image that accompanies the destructive malware.