Skip to content

Wiper

PathWiper

According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly.

PathWiper is a Windows wiper.

Background

Cisco Talos reports that this wiper overwrites file-system-related artifacts with random data produced on the fly. It enumerates the attached storage media, spawns a dedicated thread for each drive and volume across every recorded path, and overwrites those artifacts using randomly generated bytes. The wiper also pulls several NTFS file-system attributes and overwrites them too. On top of that, PathWiper wrecks files on disk by overwriting them with randomized bytes.


Source: Malpedia (Fraunhofer FKIE).