
On May 27, 2012 industry and media outlets began reporting details on a complex targeted attack known as “Flame” or “Flamer”. In some cases, this same threat was previously described as “Viper” or “Wiper”. This, currently active, attack is multi-faceted and in many ways sets a new precedence for recon and data exfiltration within this attack genre.
Skywiper is a modular, extendable and updateable threat. It is capable, but not limited to the following key espionage functions:
| Malware | |
|---|---|
| AV / MWG | Coverage is provided in the 6726 DATs released on May 29) as "Skywiper" |
| McAfee Network Security Platform | A Network Security Emergency User Defined Signature (HTTP: W32/Skywiper Activity Detected) has been created to detect this threat. The UDS is available for download via McAfee Knowledge Base article KB55447 |
| McAfee Vulnerability Manager | Pending - Coverage will be provided via an upcoming MVM/FSL release. |
| McAfee Firewall Enterprise | Related domains and IP Addresses are detected via Products with GTI configured |
| McAfee Application Control | Coverage is provided via Runtime Control |
| Vulnerability / Exploit-Specific | |
| AV / MWG | CVE-2010-2729 - N/A CVE-2010-2568 - Covered as "Exploit-CVE2010-2568" in the current DAT set. |
| McAfee Network Security Platform | CVE-2010-2729 - Coverage is provided via "NETBIOS-SS: Microsoft Windows Print Spooler Service Impersonation Vulnerability" CVE-2010-2568 - Coverage is provided via the following signatures: SMTP: Suspicious .Lnk Attachment Found / HTTP: Windows Shell Shortcut LNK File Parsing Vulnerability / HTTP: lnk File Download Detected / NETBIOS-SS: lnk File Access Detected |
| McAfee Vulnerability Manager | CVE-2010-2729 - Coverage is provided via the following MVM check: (MS10-061) Microsoft Windows Print Spooler Service Impersonation (2347290) CVE-2010-2568 - Coverage is provided via the following MVM check: (MS10-046) Microsoft Windows Shortcut Icon Loading Remote Code Execution(2286198) |
| McAfee Firewall Enterprise | Related domains and IP Addresses are detected via Products with GTI configured |
| McAfee Application Control | Coverage is provided via Runtime Control |
| Microsoft Security Advisory (2718704) | |
| AV / MWG | Coverage is provided in the 6726 DATs released on May 29) as "Skywiper". Coverage is also provided via an updated Stinger tool. |
| McAfee Network Security Platform | U/A |
| McAfee Vulnerability Manager | Covered - Microsoft Windows Unauthorized Digital Certificates Spoofing (2718704) |
| McAfee Firewall Enterprise | U/A |
| McAfee Application Control | U/A |