Duqu 2.0 Malware - Indicators of Compromise

Document created by rkent on Jun 14, 2015Last modified by rkent on Jun 14, 2015
Version 3Show Document
  • View in full screen mode

IP Addresses - Command and Control

C2 Servers
182.253.220.29
186.226.56.103

 

File Hash Values - MD5 SUM

Action Loaders

089a14f69a31ea5e9a5b375dc0c46e45

16ed790940a701c813e0943b5a27c6c1

26c48a03a5f3218b4a10f2d3d9420b97

a6dcae1c11c0d4dd146937368050f655

acbf2d1f8a419528814b2efa9284ea8b

c04724afdb6063b640499b52623f09b5

e8eaec1f021a564b82b824af1dbe6c4d

10e16e36fe459f6f2899a8cea1303f06

48fb0166c5e2248b665f480deac9f5e1

520cd9ee4395ee85ccbe073a00649602

7699d7e0c7d6b2822992ad485caacb3e

84c2e7ff26e6dd500ec007d6d5d2255e

856752482c29bd93a5c2b62ff50df2f0

85f5feeed15b75cacb63f9935331cf4e

8783ac3cc0168ebaef9c448fbe7e937f

966953034b7d7501906d8b4cd3f90f6b

a14a6fb62d7efc114b99138a80b6dc7d

a6b2ac3ee683be6fbbbab0fa12d88f73

cc68fcc0a4fab798763632f9515b3f92

 

Cores

3f52ea949f2bd98f1e6ee4ea1320e80d

c7c647a14cb1b8bc141b089775130834

 

Source Reference Links:

https://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/https://securelist.com/files/2015/06/7c6ce6b6-fee1-4b7b-b5b5-adaff0d8022f.iochttps://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/

Attachments

    Outcomes