Secret Malware in EU Attack Linked to US and British Intelligence
firstlook.org
firstlook.org
"The archive also contains the output of ProcMon,
Process Monitor, a system monitoring tool distributed
by Microsoft and commonly used in forensics and
intrusion analysis.
This file identifies the infected system and provides
a variety of interesting information about the network.
For instance:
USERDNSDOMAIN=BGC.NET
USERDOMAIN=BELGACOM
USERNAME=id051897a
USERPROFILE=C:\Users\id051897a"
Also love the comment at the end:"Below is a list of hashes for the files The Intercept is making available for download. Given that that it has been over a year since the Belgacom operation was publicly outed, The Intercept considers it likely that the GCHQ/NSA has REPLACED THEIR TOOLKIT AND NO CURRENT OPERATIONS WILL BE AFFECTED by the publication of these samples."
Currently we only know this malware was used in belgacom hack, there is still no proof it is nsa code.
We can debate about motivations and who their target really was (Belgacom may have been collateral damage), but despite "proof", there's little doubt about who wrote it.
You act like its some sort of proof, like this totalvirus upload came from Langley IP.
> Yes, just like FBI assassinating Kennedy because Oh snap cuba!
I have no doubt where this came from, despite not having Gen. Keith Alexander's email in the logs.
"Got more payload chunks. Wow, they were sloppy with this - found plenty of symbol references still in them!
So far, that makes references to LEGSPIN, WILLISCHECK, HOPSCOTCH, STARBUCKS, FOGGYBOTTOM, SALVAGERABBIT.
I believe this may be NSA's UNITEDRAKE implant architecture, specifically."
("Foggy Bottom" is an oblique reference to the US State Dept, after the DC district where it's located)
Duqu = stolen from https://en.wikipedia.org/wiki/C-Media Stuxnet = stolen from https://en.wikipedia.org/wiki/Realtek
Not hard to find a valid cert when you're a nation state.
Source: https://firstlook.org/theintercept/2014/11/12/stuxnet/
if you read the symantec pdf whitepaper, that is only how the 32 bit one works, the 64bit one works differently - something to do with winsock.
Nice one.
I'm sure all they learned about politicians/activitists and their family helped in the "negotiations" on Northern Ireland and other matters.
Of course, that situation just isn't today what it used to be.
As for the US, a lot of corps have operations and/or headquarters in Ireland for tax reasons. For example you might recall a story about Microsoft, the FBI, and email.
"This Regin driver recurrently checks
that the current IRQL (Interrupt Request Level)
is set to PASSIVE_LEVEL using the KeGetCurrentIrql()
function in many parts of the code, probably in order
to operate as silently as possible and to prevent
possible IRQL confusion. This technique is another
example of the level of precaution the developers
took while designing this malware framework."
what does that even MEAN?!A low handler priority makes sure that everything critical gets handled first and no one will get suspicious.
Accessing some calls at the wrong irql is deadly. Similarly, if you are attached as a filter you can get tons of calls, most all of which are not relevant. You must be able to quickly filter those calls or the system can become unstable.
Admittedly, the efficiency of NT's design is pretty brilliant considering that we started with TSR interrupts in DOS, but it is also fraught with danger. For instance different locking calls can only be used at certain IRQLs, otherwise you can lock the entire system. Sometimes those calls only happen with certain configurations or kernel versions.
Being an NT driver developer is maddening. The Linux driver model is much better, as there are no mixed mode calls. Interrupts are chained but your function is always at the same or lower interrupt level. Most code is also explicitly kept out of interrupts, and instead operates as usermode syscalls. You can write an entire filesystem and likely never deal with interrupts.