Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: InfoSec Handlers Diary Blog - The old new Stuxnet...DuQu? InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

The old new Stuxnet...DuQu?

Published: 2011-10-19
Last Updated: 2011-10-19 01:36:37 UTC
by Pedro Bueno (Version: 1)
0 comment(s)

Yes, the tittle probably makes no sense at first, but keep reading...:)

Today was a pretty good day if you like malware and RE...

Symantec, McAfee and F-Secure, to name a few security vendors, released information about what they are calling "DuQu"...yes, I agree that it is a terrible name, but it is because this malware creates some files on the user's temp folder, that starts with ~DQXXX.tmp (where the XXX can be any number)...

There are several common aspects between DuQu and Stuxnet that leads to the conclusion that they were written by the same group.

While the original Stuxnet was focused on Industrial systems, aka SCADA, this DuQu malware is mostly used on a recon process, and being used as an advanced RAT (Remote Administration Tool).  Forget about Gh0st RAT or BlackShades RAT, just to name two "famous" ones...those are totally amateurs when compared to DuQu.

DuQu received commands via an encrypted config file, and seems to download a password stealer that is able to record several behaviors from user and machine and send to a Command and Control IP in India.

Like some of the components of the original Stuxnet, this one was also able to decrypt and extract additional components embedded into other PE files...fantastic! 

Oh, and like Stuxnet, some components had a VALID digital signature...:)

And before I forget, according Symantec report, new samples with compilation time of October 17th were discovered and are still being checked...

Agree that it is a good day for Reverse Engineers?

_______________________________________________

Pedro Bueno (pbueno /%%/ isc. sans. org)
Twitter: http://twitter.com/besecure

Keywords: apt scada stuxnet
0 comment(s)
Diary Archives