It uses kernel drivers to decrypt and loads encrypted dynamic link library (DLL). These kernel drives act as an injection engine to load DLL. The encrypted files are stored as a .pnf file in the kernel, which is normally set up information file extension in Microsoft Windows system. Since it is remote access Trojan, it will allow the machine to download and run additional programs.
Duqu is looking like somewhat Stuxnet worm. Its kernel drives have a digitally signed certificate same as Stuxnet. Consequently, all data can be stole and computer is remotely operated by an attacker without user knowledge. Even though numerous characteristic of Duqu same as Stuxnet, but it cannot replicate by itself
"For every lock, there is someone out there trying to pick it or break in" - David Bernsteing
.
Comments
Post a Comment