bsides algiers - stuxnet - sofiane talmat

20
http://www.synapse- labs.com info@synapse- labs.com L’industrie du Malwar (Part II) : STUXNET Présentée par : Sofiane Talmat Malware research team : Sofiane Talmat (Algeria) Ehab Hussein (Egypt)

Upload: shellmates

Post on 30-Nov-2014

1.058 views

Category:

Technology


0 download

DESCRIPTION

 

TRANSCRIPT

Page 1: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

L’industrie du Malware(Part II) : STUXNET

Présentée par : Sofiane Talmat

Malware research team :Sofiane Talmat (Algeria)Ehab Hussein (Egypt)

Page 2: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Solution

Development

Security

Services

Corporate Services

Trainings

Page 3: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

FACT 1 : ~WTR4132.TMP

Page 4: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

FACT 2 : ~WTR4132.TMP

Page 5: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

FACT 3 : MRXCLS.sys

Page 6: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

FACT 4 : MRXCLS.sys

Page 7: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

FACT 5 : MRXNET.sys

Page 8: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

FACT 6 : MRXNET.sys

Page 9: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Lifecycle

Page 10: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

PRIVILEGE ESCALATION

- MS-10-073 –Win32K.sys Keyboard Layout Vulnerability

- MS-10-092 –Windows Task Scheduler Vulnerability

Page 11: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 12: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 13: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 14: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 15: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

ESP ==> > 0006F4F8 |ModuleFileName = "C:\WINDOWS\\system32\\lsass.exe"ESP+4 > 00000000 |CommandLine = NULLESP+8 > 00000000 |pProcessSecurity = NULLESP+C > 00000000 |pThreadSecurity = NULLESP+10 > 00000001 |InheritHandles = TRUEESP+14 > 0800000C |CreationFlags = CREATE_SUSPENDED|DETACHED_PROCESS|

CREATE_NO_WINDOW

ESP+18 > 00000000 |pEnvironment = NULLESP+1C > 00000000 |CurrentDir = NULLESP+20 > 0006F13C |pStartupInfo = 0006F13CESP+24 > 0006F730 \pProcessInfo = 0006F730.

Page 16: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 17: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 18: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Page 19: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

• stuxnet: references

http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_stuxnet_dossier.pdf

http://go.eset.com/us/resources/white-papers/Stuxnet_Under_the_Microscope.pdf

Page 20: BSides Algiers - Stuxnet - Sofiane Talmat

http://www.synapse-labs.com [email protected]

Questions

Facebook.com/Synapse.LabsTwitter : @Synapse_Labs