Duqu

Duqu is a collection of computer malware discovered on 1 September 2011, thought by Kaspersky Labs to be related to the Stuxnet worm[1] and to have been created by Unit 8200.[2][3] Duqu has exploited Microsoft Windows's zero-day vulnerability. The Laboratory of Cryptography and System Security (CrySyS Lab)[4] of the Budapest University of Technology and Economics in Hungary discovered the threat, analysed the malware, and wrote a 60-page report[5] naming the threat Duqu.[6] Duqu got its name from the prefix "~DQ" it gives to the names of files it creates.[7]

Nomenclature

The term Duqu is used in a variety of ways:

  • Duqu malware is a variety of software components that together provide services to the attackers. Currently this includes information stealing capabilities and in the background, kernel drivers and injection tools. Part of this malware is written in unknown high-level programming language,[8] dubbed "Duqu framework". It is not C++, Python, Ada, Lua and many other checked languages. However, it is suggested that Duqu may have been written in C with a custom object oriented framework and compiled in Microsoft Visual Studio 2008.[9]
  • Duqu flaw is the flaw in Microsoft Windows that is used in malicious files to execute malware components of Duqu. Currently one flaw is known, a TrueType-font related problem in win32k.sys.
  • Operation Duqu is the process of only using Duqu for unknown goals. The operation might be related to Operation Stuxnet.

Relationship to Stuxnet

Symantec, based on the CrySyS team managed by Dr Thibault Gainche report, continued the analysis of the threat, which it called "nearly identical to Stuxnet, but with a completely different purpose", and published a detailed technical paper on it with a cut-down version of the original lab report as an appendix.[7][10] Symantec believes that Duqu was created by the same authors as Stuxnet, or that the authors had access to the source code of Stuxnet. The worm, like Stuxnet, has a valid, but abused digital signature, and collects information to prepare for future attacks.[7][11] Mikko Hyppönen, Chief Research Officer for F-Secure, said that Duqu's kernel driver, JMINET7.SYS, was so similar to Stuxnet's MRXCLS.SYS that F-Secure's back-end system thought it was Stuxnet. Hyppönen further said that the key used to make Duqu's own digital signature (only observed in one case) was stolen from C-Media, located in Taipei, Taiwan. The certificates were due to expire on 2 August 2012 but were revoked on 14 October 2011 according to Symantec.[10]

Another source, Dell SecureWorks, reports that Duqu may not be related to Stuxnet.[12] However, there is considerable and growing evidence that Duqu is closely related to Stuxnet.

Experts compared the similarities and found three points of interest:

  • The installer exploits zero-day Windows kernel vulnerabilities.
  • Components are signed with stolen digital keys.
  • Duqu and Stuxnet are both highly targeted and related to the nuclear program of Iran.

Microsoft Word zero-day exploit

Like Stuxnet, Duqu attacks Microsoft Windows systems using a zero-day vulnerability. The first-known installer (AKA dropper) file recovered and disclosed by CrySyS Lab uses a Microsoft Word document that exploits the Win32k TrueType font parsing engine and allows execution.[13] The Duqu dropper relates to font embedding, and thus relates to the workaround to restrict access to T2EMBED.DLL, which is a TrueType font parsing engine if the patch released by Microsoft in December 2011 is not yet installed.[14] Microsoft identifier for the threat is MS11-087 (first advisory issued on 13 November 2011).[15]

Purpose

Duqu looks for information that could be useful in attacking industrial control systems. Its purpose is not to be destructive; the known components are trying to gather information.[16] However, based on the modular structure of Duqu, special payload could be used to attack any type of computer system by any means and thus cyber-physical attacks based on Duqu might be possible. However, use of personal computer systems has been found to delete all recent information entered on the system, and in some cases total deletion of the computer's hard drive. Internal communications of Duqu are analysed by Symantec,[7] but the actual and exact method how it replicates inside an attacked network is not yet fully known. According to McAfee, one of Duqu's actions is to steal digital certificates (and corresponding private keys, as used in public-key cryptography) from attacked computers to help future viruses appear as secure software.[17] Duqu uses a 54×54 pixel JPEG file and encrypted dummy files as containers to smuggle data to its command and control center. Security experts are still analyzing the code to determine what information the communications contain. Initial research indicates that the original malware sample automatically removes itself after 36 days (the malware stores this setting in configuration files), which would limit its detection.[10]

Key points are:

  • Executables developed after Stuxnet using the Stuxnet source code that have been discovered.
  • The executables are designed to capture information such as keystrokes and system information.
  • Current analysis shows no code related to industrial control systems, exploits, or self-replication.
  • The executables have been found in a limited number of organizations, including those involved in the manufacturing of industrial control systems.
  • The exfiltrated data may be used to enable a future Stuxnet-like attack, or might already have been used as the basis for the Stuxnet attack.

Command and control servers

Some of the command and control servers of Duqu have been analysed. It seems that the people running the attack had a predilection for CentOS 5.x servers, leading some researchers to believe that they had a[18] zero-day exploit for it. Servers are scattered in many different countries, including Germany, Belgium, Philippines, India and China. Kaspersky has published multiple blogposts on the command and control servers.[19]

See also

References

  1. ^ How Israel Caught Russian Hackers Scouring the World for U.S. Secrets, New York Times
  2. ^ NSA, Unit 8200, and Malware Proliferation Archived 25 October 2017 at the Wayback Machine Jeffrey Carr, Principal consultant at 20KLeague.com; Founder of Suits and Spooks; Author of “Inside Cyber Warfare (O’Reilly Media, 2009, 2011), medium.com, Aug 25, 2016
  3. ^ Cornish, Paul (4 November 2021). The Oxford Handbook of Cyber Security. Oxford University Press. ISBN 978-0-19-252101-9. Foreign sources routinely assert that Unit 8200 contribured to Stuxnet, Flame, Duqu and other sophisticated cyber campaigns.
  4. ^ "Laboratory of Cryptography and System Security (CrySyS)". Retrieved 4 November 2011.
  5. ^ "Duqu: A Stuxnet-like malware found in the wild, technical report" (PDF). Laboratory of Cryptography of Systems Security (CrySyS). 14 October 2011.
  6. ^ "Statement on Duqu's initial analysis". Laboratory of Cryptography of Systems Security (CrySyS). 21 October 2011. Archived from the original on 4 October 2012. Retrieved 25 October 2011.
  7. ^ a b c d "W32.Duqu – The precursor to the next Stuxnet (Version 1.4)" (PDF). Symantec. 23 November 2011. Archived from the original (PDF) on 13 December 2011. Retrieved 30 December 2011.
  8. ^ Shawn Knight (2012) Duqu Trojan contains mystery programming language in Payload DLL
  9. ^ "Securelist | Kaspersky's threat research and reports". 12 September 2023.
  10. ^ a b c Zetter, Kim (18 October 2011). "Son of Stuxnet Found in the Wild on Systems in Europe". Wired. Retrieved 21 October 2011.
  11. ^ "Virus Duqu alarmiert IT-Sicherheitsexperten". Die Zeit. 19 October 2011. Retrieved 19 October 2011.
  12. ^ "Spotted in Iran, trojan Duqu may not be "son of Stuxnet" after all". 27 October 2011. Retrieved 27 October 2011.
  13. ^ "Microsoft issues temporary 'fix-it' for Duqu zero-day". ZDNet. Archived from the original on 6 November 2011. Retrieved 5 November 2011.
  14. ^ "Microsoft Security Advisory (2639658)". Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege. 3 November 2011. Retrieved 5 November 2011.
  15. ^ "Microsoft Security Bulletin MS11-087 - Critical". Retrieved 13 November 2011.
  16. ^ Steven Cherry, with Larry Constantine (14 December 2011). "Sons of Stuxnet". IEEE Spectrum. Archived from the original on 19 July 2012.
  17. ^ Venere, Guilherme; Szor, Peter (18 October 2011). "The Day of the Golden Jackal – The Next Tale in the Stuxnet Files: Duqu". McAfee. Archived from the original on 31 May 2016. Retrieved 19 October 2011.
  18. ^ Garmon, Matthew. "In Command & Out of Control". Matt Garmon. DIG.
  19. ^ Kamluk, Vitaly (30 November 2011). "The Mystery of Duqu: Part Six (The Command and Control servers)". Securelist by Kaspersky. Archived from the original on 7 June 2022. Retrieved 7 June 2022.

Read other articles:

Dolores HartHart pada tahun 1959LahirDolores Hicks20 Oktober 1938 (umur 85)Chicago, Illinois, A.S.Tempat tinggalBethlehem, ConnecticutKebangsaanAmerikaNama lainRev. Mother Dolores Hart, O.S.B.PendidikanSekolah Katolik St. GregoryAlmamaterKolese MarymountTahun aktif1963–sekarang (relijius)1947–63 (aktris)Kota asalChicago, IllinoisSitus webEar of the heart, Ignatious  Rev. Mother Dolores Hart (kelahiran 20 Oktober 1938) merupakan seorang suster Katolik Roma Amerika...

 

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Februari 2023. Bandar Udara IsfaraIATA: noneICAO: none Bandar Udara IsfaraLokasi bandar udara di TajikistanInformasiJenisPublikPengelolaPemerintahMelayaniIsfara, TajikistanKetinggian dpl858 mdplKoordinat40°07′18″N 070°39′55″E / 40...

 

Citra satelit Pulau Wake Pulau Wake (bahasa Inggris: Wake Island) adalah sebuah atol koral dengan garis pantai sepanjang 19,3 km yang terletak di Samudra Pasifik bagian utara. Letaknya 3.700 km di sebelah barat Hawaii dan 2.430 km di sebelah timur Guam. Pulau terbesarnya (juga disebut Pulau Wake) merupakan pusat aktivitas wilayah ini dan memiliki landasan pacu sepanjang 3.000 m. Pulau ini dinamakan dari Kapten Willaim Wake, kapten kapal Prince William Henry yang berkunjung pada...

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Februari 2023. SDN 001 GalangInformasiJenisSekolah NegeriAlamatLokasiSembulang - Pulau Galang, Batam, Kepri,  IndonesiaMoto SDN 001 Galang, merupakan salah satu Sekolah Menengah Dasar Negeri yang ada di Provinsi Kepulauan Riau, yang beralamat di Sembulang - Pul...

 

مايكل أبتيد (بالإنجليزية: Michael Apted)‏   أبتيد سنة 2013    معلومات شخصية اسم الولادة (بالإنجليزية: Michael David Apted)‏  الميلاد 10 فبراير 1941 [1][2][3]  أيلزبري[4]  الوفاة 7 يناير 2021 (79 سنة) [5][6]  لوس أنجلوس[5][4]  مواطنة المملكة المتحدة  ع�...

 

يودنبورغ    شعار الاسم الرسمي (بالألمانية: Judenburg)‏    الإحداثيات 47°10′21″N 14°39′37″E / 47.1725°N 14.660277777778°E / 47.1725; 14.660277777778  [1] تاريخ التأسيس 1074  تقسيم إداري  البلد النمسا[2][3]  التقسيم الأعلى منطقة مورتال  عاصمة لـ منطقة مورتال  خصائ...

Cet article est une ébauche concernant la politique française et l’Ille-et-Vilaine. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. 1953 1965 Élections municipales de 1959 en Ille-et-Vilaine les 8 et 15 mars 1959 Type d’élection Élections municipales modifier - modifier le code - voir Wikidata  Les élections municipales en Ille-et-Vilaine ont eu lieu les 8 et 15 mars 1959. Maires sortants et ...

 

Cabinet of Yemen Ministry of TourismEmblem of YemenMinistry overviewFormed1990 (1990)JurisdictionGovernment of YemenHeadquartersAden, Sana'aMinister responsibleMoammar Al-Eryani, Minister of Information, Culture and Tourism The Ministry of Tourism (Arabic: وزارة السياحة) is a cabinet ministry of Yemen. List of ministers Moammar Al-Eryani (18 December 2020 – present)[1] Mohamed al-Qubati (18 September 2016 – December 2020)[2] Moammar Al-Eryani (7 November ...

 

本條目存在以下問題,請協助改善本條目或在討論頁針對議題發表看法。 此條目需要擴充。 (2013年1月1日)请協助改善这篇條目,更進一步的信息可能會在討論頁或扩充请求中找到。请在擴充條目後將此模板移除。 此條目需要补充更多来源。 (2013年1月1日)请协助補充多方面可靠来源以改善这篇条目,无法查证的内容可能會因為异议提出而被移除。致使用者:请搜索一下条目的...

Extinct Old South Arabian language of eastern Yemen and Oman HadhramauticHadramiNative toYemen, Oman, Saudi ArabiaEra800 BC – 600 ADLanguage familyAfro-Asiatic SemiticSouthWesternOld South ArabianHadhramauticWriting systemAncient South ArabianLanguage codesISO 639-3xhdLinguist ListxhdGlottologhadr1235Kingdom of Hadramawt in 400 BC Ḥaḍramautic or Ḥaḍramitic was the easternmost of the four known languages of the Old South Arabian subgroup of the Semitic languages. It was used in ...

 

Czech-born French composer Anton Reicha, 1815 Wind Quintets Op. 88 No. 2 in E-flat major – 1. Lento – Allegro Moderato No. 2 in E-flat major – 2. Allegretto No. 2 in E-flat major – 3. Poco andante No. 2 in E-flat major – 4. Allegretto No. 3 in G major – 1. Lento – Allegro assai No. 3 in G major – 2. Andante No. 3 in G major – 3. Scherzo, Allegro vivo No. 3 in G major – 4. Finale, Allegro vivace Performed by the Soni Ventorum Wind Quintet Problems playing these files? See m...

 

Oath taken by a new president of the United States Chief Justice John Roberts administering the presidential oath of office to Joe Biden on January 20, 2021. The oath of office of the president of the United States is the oath or affirmation that the president of the United States takes upon assuming office. The wording of the oath is specified in Article II, Section One, Clause 8, of the United States Constitution, and a new president must take it before exercising or carrying out any offici...

Repubblica Cisalpina (dettagli) (dettagli) Motto: Libertà Eguaglianza Repubblica Cisalpina - LocalizzazioneLa Repubblica Cisalpina nel 1797 Dati amministrativiNome completoRepubblica Cisalpina Lingue ufficialiitaliano Lingue parlateemiliano, romagnolo, lombardo, veneto CapitaleMilano[1]  (127000 ab. / 1798) Dipendente da Francia PoliticaForma di StatoRepubblica sorella Forma di governoRepubblica direttoriale GovernoDirettorio Organi deliberativi Gran Consigli...

 

Film festival 8th Berlin International Film FestivalFestival posterLocationWest Berlin, GermanyFounded1951AwardsGolden Bear (Smultronstället)Festival date27 June – 8 July 1958WebsiteWebsiteBerlin International Film Festival chronology9th 7th The 8th annual Berlin International Film Festival was held from 27 June to 8 July 1958 with the Zoo Palast as the main venue.[1] The festival was opened by then West Berlin's newly elected mayor Willy Brandt.[2] The Golden Bear was awar...

 

American actor (1892–1943) George CooperCooper in Sitting on the Moon (1936)BornGeorge Cooper Healey(1892-12-12)December 12, 1892Newark, New Jersey, U.S.DiedDecember 9, 1943(1943-12-09) (aged 50)Sawtelle, California, U.S.OccupationActorYears active1911–1940Spouse Carolina Edwina Weiss ​ ​(m. 1915)​[1]Children4 George Cooper Healey (December 12, 1892 – December 9, 1943) was an American actor of the silent film era.[2] Coope...

Юрій Андрійович   Народження: 1160Владимир Смерть: 1190Тифліс, Грузинське царство Батько: Андрій Боголюбський Шлюб: Тамара Велика  Медіафайли у Вікісховищі Юрій АндрійовичНародився1160ВладимирПомер1190Тифліс, Грузинське царствоДіяльністьвоєначальникТитулкнязьВійськ�...

 

Cartilaginous fish in the order Chimaeriformes This article is about the cartilaginous fish order. For the namesake genus, see Chimaera (genus). For the mythological beast, see Chimera (mythology). For other uses, see Chimera. Ghost shark redirects here. For the film, see Ghost Shark (film). ChimaerasTemporal range: Early Carboniferous–Present PreꞒ Ꞓ O S D C P T J K Pg N Hydrolagus colliei (Chimaeridae) Scientific classification Domain: Eukaryota Kingdom: Animalia Phylum: Chordata Class...

 

Pour les articles homonymes, voir John Davis et Davis. John W. DavisPortrait de John William Davis.FonctionsReprésentant des États-UnisAvocat général des États-UnisWilliam Marshall Bullitt (en)Alexander Campbell King (en)AmbassadeurBiographieNaissance 13 avril 1873Clarksburg (comté de Harrison)Décès 24 mars 1955 (à 81 ans)CharlestonSépulture Locust Valley Cemetery (en)Nationalité américaineFormation Université Washington et LeeFaculté de droit de l'université Washington e...

THE AGIT: Ryeo Wook - Ever Lasting StarTur  Korea Selatan oleh RyeowookTHE AGIT: Ryeo Wook - Ever Lasting Star PosterThe Little PrinceMulai19 Februari 2016 (2016-02-19)Berakhir13 Maret 2016 (2016-03-13)Penampilan6Situs webryeowook.smtown.com THE AGIT: Ryeo Wook - Ever Lasting Star merupakan konser solo pertama anggota boy band Korea Selatan Super Junior, Ryeowook untuk mempromosikan album mini perdananya The Little Prince. Dan merupakan bagian keempat dari seri konser SMTOWN TH...

 

Ne doit pas être confondu avec Frédéric Curie. Pour les articles homonymes, voir Joliot-Curie et Famille Curie. Frédéric Joliot-CurieFrédéric Joliot-Curie en 1948.FonctionsPrésidentSociété française de physique1946-1949Louis Dunoyer de SegonzacLouis de BroglieHaut-commissaire à l'énergie atomique18 octobre 1945 - 28 avril 1950Francis PerrinDirecteur général du Centre national de la recherche scientifique1944-1946Charles JacobGeorges TeissierProfesseurCollège de France1938-195...