Difference between revisions of "The mystery of Duqu: part ten"
Jump to navigation
Jump to search
m (Remplacement de texte — « |Editor=Kaspersky » par « |Editor=Kaspersky lab ») |
m (1 revision imported) |
(No difference)
|
Revision as of 16:24, 7 February 2015
(Publication) Google search: [1]
The mystery of Duqu: part ten | |
---|---|
Botnet | Duqu |
Malware | Duqu (bot) |
Botnet/malware group | |
Exploit kits | |
Services | |
Feature | |
Distribution vector | |
Target | |
Origin | |
Campaign | |
Operation/Working group | |
Vulnerability | |
CCProtocol | |
Date | 2012 / 27 mars 2012 |
Editor/Conference | Kaspersky lab |
Link | http://www.securelist.com/en/blog/208193425/The mystery of Duqu Part Ten www.securelist.com (www.securelist.com Archive copy) |
Author | Alexander Gostev |
Type |
Abstract
“ At the end of the last year the authors of Duqu and Stuxnet tried to eliminate all traces of their activity. They wiped all servers that they used since 2009 or even earlier. The cleanup happened on October 20.
There were virtually no traces of Duqu since then. But several days ago our colleagues in Symantec announced that they found a new "in-the-wild" driver that is very similar to known Duqu drivers. Previous modifications of Duqu drivers were compiled on Nov 3 2010 and Oct 17 2011, and the new driver was compiled on Feb 23 2012.
Bibtex
@misc{Lua error: Cannot create process: proc_open(/dev/null): failed to open stream: Operation not permitted2012BFR970, editor = {Kaspersky lab}, author = {Alexander Gostev}, title = {The mystery of Duqu: part ten}, date = {28}, month = Mar, year = {2012}, howpublished = {\url{http://www.securelist.com/en/blog/208193425/The_mystery_of_Duqu_Part_Ten www.securelist.com}}, }