PWS-Duqu

PWS-Duqu Description

PWS-Duqu, also detected as Duqu, PWS-Duqu.dr and PWS-Duqu!rootkit, is a backdoor Trojan and successor of the most complicated and dangerous attack of this decade named Stuxnet. Basically, Duqu is based on Stuxnet, and some of its parts are almost identical to Stuxnet, but have a totally different aim. In contrary to Stuxnet, PWS-Duqu does not contain PLC functionality like Stuxnet. Instead, the code which is spread via exploitation, installs drivers and encrypted DLLs that operate very similar to the original Stuxnet code. The driver's code, encryption keys and methods used for the PWS-Duqu's injection attack are very similar to Stuxnet. The aim of Duqu is to collect intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily execute a future attack against another third-party. Attackers are looking for information such as design documents that could help them start a future attack on an industrial control facility. Duqu does not involve any code associated with industrial control systems and does not replicate itself. Duqu is used to install another infostealer that could record keystrokes and steal other targeted computer system's information. Duqu uses HTTP and HTTPS to communicate with a command-and-control (C&C) server that in the course of writing is still functional.

PWS-Duqu, also known as Duqu, has an interesting way of stealing data. Duqu utilizes a JPG image file to transmit stolen information from an infected system. Duqu is known to send an http request to a server identified as 206.183.111.97 (site URL: canoyraqomez.rapidns.com) and returns a blank JPG image. The image file, if properly access, will return a photo of a NASA galaxy image. Contained in the image is the stolen data that can easily be transmitted to a remote location by Duqu. It is highly suggestive that Duqu be removed before this is able to happen.

Technical Information

Registry Details

PWS-Duqu creates the following registry entry or registry entries:
RegistryKey
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JmiNET3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run '[random string]'
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XTray.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run 'tmp'

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.


HTML is not allowed.