This is the Trend Micro detection for the configuration file of the TROJ_DUQU malware family.
File size: 6,750 bytes
File type: Other
Initial samples received date: 19 Oct 2011
NOTES:
This is the Trend Micro detection for the configuration file of the TROJ_DUQU malware family.
It contains the following configurations:
- File path of component files
- Processes where TROJ_DUQU.ENC will be injected into
- Service registry key
- Websites it will try to connect to for DNS checking
The configuration file analyzed has the following settings:
- Service registry key:
- File path of component files:
- %System Root%\inf\cmi4432.pnf - TROJ_DUQU.ENC
- %System Root%\inf\cmi4464.pnf - TROJ_DUQU.CFG
- %System Root%\inf\netp191.pnf - TROJ_DUQU.ENC
- %System Root%\inf\netp192.pnf - TROJ_DUQU.CFG
- %System%\Drivers\cmi4432.sys - RTKT_DUQU.A
- %System%\Drivers\jminet7.sys - RTKT_DUQU.A
- Websites it will try to connect to for DNS checking:
- kasperskychk.dyndns.org
- www.microsoft.com
- Processes wherein TROJ_DUQU.ENC will be injected into
- explorer.exe
- firefox.exe
- iexplore.exe
- pccntmon.exe
Connect with us on
| | | |