Jump to content
Tuts 4 You

Recommended Posts

Posted (edited)

Anyone have a copy of this new malware that was discovered last week?

Edited by PaperBall
Posted

binaries have not been made public yet, afaik, as they are still analyzing it in greater detail.

Posted

the symantec whitepaper can be found here


/>http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf

THere is supposed to be a 2x page attachment (the inital analysis), but i can only see the 14p symantec analysis...

Posted
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=1210
Posted
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=1210

I hope there are no moral issues with me attaching them here...?

If so, please let me know...

drivers.rar

pass: malware

c9a31ea148232b201fe7cb7db5c75f5e.zip

pass: infected

c9a31ea148232b201fe7cb7db5c75f5e.zip

drivers.rar

Posted
I hope there are no moral issues with me attaching them here...?

If so, please let me know...

No... it's ok! enjoy! :)

Regards

Posted

http://www.securelist.com/en/blog/208193182/The_Mystery_of_Duqu_Part_One
Posted

It's an industrial rootkit..The PLC payload and leaked PKI usage is all that is really unique. It Does some DKOM and stuff with tables, or at least it did when I looked at the last one.

I'm not going to use what little time I have to re-analyse anything

Posted

Win32/Duqu: It’s A Date


http://blog.eset.com/2011/10/25/win32duqu-it%e2%80%99s-a-date

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...