Archive

Archive for November, 2011

CrySyS Releases Duqu Detector

آبان ۳۰م, ۱۳۹۰ ۱ comment

The lab that par­tic­i­pated in the dis­cov­ery of the Duqu tro­jan has devel­oped a detec­tor toolkit that can find Duqu infec­tions on a com­puter or in a whole net­work. The toolkit, released by the Lab­o­ra­tory of Cryp­tog­ra­phy and Sys­tem Secu­rity (CrySyS), uses sig­na­ture and heuris­tics meth­ods to find traces of Duqu infec­tions even when bits of the mal­ware have already been removed from a PC.

The toolkit searches for a range of dif­fer­ent Duqu related sus­pi­cious files and known indi­ca­tors to detect the cur­rent or past pres­ence of the tro­jan. How­ever, as with all anom­aly detec­tion tools, it is pos­si­ble that it gen­er­ates false positives.

There­fore, pro­fes­sional per­son­nel is needed to elab­o­rate the result­ing log files of the tool and decide about fur­ther steps.

The toolkit, which includes the source code, can be down­loaded from here

http://www.honeynet.ir/software/duqu/duqudetector-v1_02.zip

Share
Categories: General Tags: