Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 06-11-2015, 04:41
Anticode Anticode is offline
Friend
 
Join Date: Jan 2002
Posts: 49
Rept. Given: 24
Rept. Rcvd 6 Times in 6 Posts
Thanks Given: 22
Thanks Rcvd at 24 Times in 8 Posts
Anticode Reputation: 6
Doqu 2.0 analysis

https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns.pdf
Reply With Quote
The Following 7 Users Say Thank You to Anticode For This Useful Post:
an0rma1 (06-18-2015), niculaita (06-11-2015), Notmex (06-18-2015), professor.frink (06-21-2015), SinaDiR (06-12-2015), TQN (06-11-2015), uranus64 (06-18-2015)
  #2  
Old 06-13-2015, 03:34
Insid3Code's Avatar
Insid3Code Insid3Code is offline
Family
 
Join Date: May 2013
Location: Algeria
Posts: 84
Rept. Given: 47
Rept. Rcvd 60 Times in 30 Posts
Thanks Given: 24
Thanks Rcvd at 108 Times in 56 Posts
Insid3Code Reputation: 60
Duqu 2.0 please correct topic title!

Malware samples (Indicators of compromise) from kernelmode.info
PHP Code:
http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3900 
Archive Password: infected
Attached Files
File Type: zip Indicators of compromise.zip (160.6 KB, 21 views)
Reply With Quote
The Following User Says Thank You to Insid3Code For This Useful Post:
niculaita (06-20-2015)
  #3  
Old 06-18-2015, 17:30
an0rma1 an0rma1 is offline
Friend
 
Join Date: Feb 2002
Posts: 203
Rept. Given: 101
Rept. Rcvd 29 Times in 17 Posts
Thanks Given: 359
Thanks Rcvd at 104 Times in 41 Posts
an0rma1 Reputation: 29
great articles, i've read all the docs this monday, INCREDIBLE WORK here

They think this software is worth 50M$.... hats off for this work, they are truly hero coders... even when they work coding APTs
Reply With Quote
  #4  
Old 06-19-2015, 04:51
maktm maktm is offline
Friend
 
Join Date: Apr 2015
Posts: 23
Rept. Given: 0
Rept. Rcvd 4 Times in 2 Posts
Thanks Given: 8
Thanks Rcvd at 16 Times in 8 Posts
maktm Reputation: 4
What really surprised me was the fact that it has signed drivers. That was pretty entertaining to read about
Reply With Quote
  #5  
Old 06-20-2015, 03:00
gigaman gigaman is offline
Friend
 
Join Date: Jun 2002
Posts: 87
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 14 Times in 11 Posts
gigaman Reputation: 4
Well, signed drivers are not that surprising, there were quite a few of those already.

However, is there a sample (of the signed driver) available here? The files posted on kernelmode.info don't seem to be signed.
Reply With Quote
  #6  
Old 06-20-2015, 23:02
Insid3Code's Avatar
Insid3Code Insid3Code is offline
Family
 
Join Date: May 2013
Location: Algeria
Posts: 84
Rept. Given: 47
Rept. Rcvd 60 Times in 30 Posts
Thanks Given: 24
Thanks Rcvd at 108 Times in 56 Posts
Insid3Code Reputation: 60
Quote:
Originally Posted by gigaman View Post
Well, signed drivers are not that surprising, there were quite a few of those already.

However, is there a sample (of the signed driver) available here? The files posted on kernelmode.info don't seem to be signed.
MD5: 92e724291056a5e30eca038ee637a23f
Certificate Serial number of Foxconn: ‎256541e204619033f8b09f9eb7c88ef8

Attached from kernelmode.info
Attached Files
File Type: rar 92e724291056a5e30eca038ee637a23f .rar (14.2 KB, 12 views)
__________________
Computer Forensics
Reply With Quote
  #7  
Old 06-21-2015, 04:54
gigaman gigaman is offline
Friend
 
Join Date: Jun 2002
Posts: 87
Rept. Given: 0
Rept. Rcvd 3 Times in 2 Posts
Thanks Given: 0
Thanks Rcvd at 14 Times in 11 Posts
gigaman Reputation: 4
Ah, my bad, I was checking only the first batch in the beginning of the thread.
Thanks a lot.
Reply With Quote
  #8  
Old 06-22-2015, 03:01
dyn!o's Avatar
dyn!o dyn!o is offline
Friend
 
Join Date: Nov 2003
Location: Own mind
Posts: 214
Rept. Given: 1
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
dyn!o Reputation: 1
Still wondering why the developers did not transform classic machine code into custom architecture run on custom interpreter (security of critical places).

Considering such a step the analysis we read would be nearly impossible to complete (in reasonable time)...
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware Analysis ldmd General Discussion 7 03-09-2025 18:42
ahk malware analysis dion General Discussion 0 12-20-2021 08:50
About Android Apps Analysis Mayo General Discussion 5 07-23-2014 21:50


All times are GMT +8. The time now is 19:29.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )