70 likes | 235 Views
DuQu. Presented by Ravil Nazipov. In which countries DuQu was detected?. How it works?. Payload types. Info-stealer. List of running processes, information about the current user and the domain List of logical drives, including network drives Screenshots
E N D
DuQu Presented by RavilNazipov
Payload types. Info-stealer • List of running processes, information about the current user and the domain • List of logical drives, including network drives • Screenshots • Addresses of network interfaces, routing tables • Logfilekeyboard keystrokes; • Full list of files on all drives • List of computers in local workgroup
Reconnaissance type • Whether the computer is part of a domain • OS version • Name of current user • List of network devices • System and local memory and time zone • Checking for domain membership