Welcome Guest. | Log In | Register | Membership Benefits
  • |   Email this page E-mail
  • |  Print Print
  • |   Bookmark and Share

Five Things To Do To Defend Against Duqu

Protect your infrastructure from Duqu in the interim, just in case -- with a new "hot fix" released by Microsoft, among other precautions

Nov 03, 2011 | 08:39 PM | 

By Kelly Jackson Higgins
Dark Reading
Whether Duqu is related to Stuxnet's authors or its source code is the least of your worries if your organization ends up in the bull's eye of this new targeted attack. Microsoft says it considers the threat "low risk" at this point. Trouble is, the names of the organizations that have been targeted thus far have been kept confidential, so we don't know just what Duqu is after exactly, and whether it's focused on a particular industry or region.

"I don't expect Duqu to stop. It looks to be manned on the inside and not on autopilot -- they are actively setting up new modules, etc., to keep the operation alive," says Don Jackson, a director with Dell Secureworks Counter Threat Unit. "So [right now] it's an intelligence game."

Even so, there are still some things organizations can do to protect themselves while the world waits for more information on this attack, as well as for Microsoft's patch for the zero-day flaw that was exploited and used with Word to spread the infection. Microsoft late today issued a "hot fix" along with an advisory about Duqu and assured users that antivirus vendors in its MAPP program would soon be updating their products with Duqu signatures very soon.

Even if you're not a certificate authority or manufacturing firm -- the two industries cited publicly so far as having Duqu victims -- security experts say there are some steps you can take to help protect your infrastructure from this new targeted attack.

1. Install the just-released "hot fix" from Microsoft and workaround.
Microsoft is working on a patch, and it will do so via its regular security bulletin release -- just not in time for next week's batch. So in the meantime, Microsoft today began offering a hot fix for the threat that blocks access to t2embed.dll used in the zero-day attack in Duqu.

The flaw lays in the Win32k TrueType font parsing engine, according to Microsoft: "An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. We are aware of targeted attacks that try to use the reported vulnerability; overall, we see low customer impact at this time. This vulnerability is related to the Duqu malware," Microsoft said in an advisory today.

Jerry Bryant, group manager for response communications in Microsoft's Trustworthy Computing Group, says Microsoft is closely monitoring further developments with Duqu. "As previously stated, the risk for customers remains low. However, that is subject to change, so we encourage customers to either apply the workaround or ensure their anti-malware vendor has added new signatures based on the information we’ve provided them to ensure protections are in place for this issue," he says.

2. Run updated anti-malware -- and use standard security best practices.
Not all antivirus products can detect Duqu yet, but security experts say to keep updating to be sure you get protection for Duqu as soon as it's released.

"Detections related to Duqu are mapped to the W32.Duqu family of signatures. We also highly encourage people not to click on attachments in email that seems suspicious, even if it comes from someone they know," says Kevin Haley, director of product management for Symantec.

Secureworks recommends using any host-based protection in addition to the typical network monitoring and user access controls that would help thwart Duqu. Tarek Saadawi, professor of electrical engineering at The City College of New York’s Grove School of Engineering, says because Duqu sniffs keyboard strokes and tries to steal passwords to internal systems, users should also protect their home computers and networks. Aside from updating AV and Windows, be sure to update third-party applications and shut down computers at night, he says.

3. Scan or filter Word documents from unknown sources.
One handy tool here is Microsoft's MOICE (Microsoft Office Isolated Conversion Environment), which checks for malformed Word documents, Secureworks' Jackson says. "That's how Duqu starts: with a malformed Word file. It's playing a trick on Microsoft Word to run this code," he says.

Jackson suggests filtering Word documents from unknown sources and scanning them with MOICE until there's a patch for the new zero-day attack. Another option is to use something like FireEye's software: "FireEye loads the Word document inside the VM and [executes] malicious detection," he says.

4. Monitor for traffic from potentially infected machines trying to "phone home" to Duqu.
Be on the lookout for machines trying to connect to a Duqu command-and-control (C&C) server or trying to resolve to a Duqu-related domain. Two C&C servers have been taken down thus far, but there are likely new ones. The IP addresses of the C&Cs that were found and ultimately shuttered: 206.183.111.97 and 77.241.93.160.

"I'm confident that there are other command-and-control servers either going up now or that are already up," Jackson says. "We are a step behind them in spotting new ones.

"Duqu has a stay-alive module … and has the ability to change itself, so anything you can do to block IP addresses will help," he says.

5. Watch for any Port 443 traffic that's unencrypted, and keep an eye out for ~DQ files.
Watching for unencrypted traffic on the HTTP-S or SSL-based traffic port can help detect malware, including a possible Duqu infection. "If it's not encrypted [traffic there], it's probably bad," says Secureworks' Jackson.

Meanwhile, a Duqu-infected file may start with "~DQ" in the Windows temporary file directory, so be on the lookout for that as well, Secureworks recommends.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Advanced Threats Reports

report Smarter, Stealthier, Sneakier Malware
Increasingly sophisticated and targeted attacks are making it more difficult for organizations to detect and defend against the latest malware. In this compendium of recent coverage from Dark Reading, you?ll get a look at some of the newest -- and most dangerous -- malware on the Web, and what you can do to stop it.

report Secure Software Development Lifecycles: Reducing Risk Throughout the App Dev Process
The application layer has long topped the attacker hit list, and we continue to hear about data breaches exploiting software vulnerabilities. Yet secure application development remains a low priority in most enterprises. In this report, we provide a blueprint for making security an integral part of the software development life cycle.

report Stuxnet Reality Check: Are You Prepared for a Similar Attack?
Stuxnet is a sophisticated, targeted weapon that proved utilities' seemingly isolated SCADA networks could be compromised, potentially disrupting energy production and distribution. In this report, we'll explain how Stuxnet penetrated Iranian nuclear facilities and propagated through their networks, and guide you in protecting against a comparable attack on your organization.

Other reports from the Advanced Threats Tech Center:

Related Content

Proactively Eliminate Risk in Software: HP Fortify Software Security Center
With business software virtually accessible from anywhere, applications now overreach standard perimeter defenses. Enterprises are finding that the effective way to secure software is by employing a Software Security Assurance (SSA) program to proactively eradicate risk.

Expert Guide to Application Security - Real-time Hybrid Analysis
Explore the next generation of hybrid security analysis - what it is, how it works, and its benefits. This white paper details how hybrid application security enables organizations to resolve critical software security issues faster and at a lower cost than any other available technology.

A Mainstay Partners Study: Does Application Security Pay?
Measuring the Business Impact of Software Security Assurance Solutions: a study of 17 organizations that implemented solutions from Fortify Software, combining industry research and benchmark analysis to identify, qualify, and quantify the full range of benefits seen from their SSA investments.

Aberdeen Benchmark Report: Securing Your Applications
Is application security actually "free?" Aberdeen's research confirms that the annual cost of application security initiatives is outweighed by the benefits. Review how all respondents, from Best-in-Class to Laggards, experienced a positive return on their annual application security investments.

White Paper: Rationalizing AppSec Using Fortify
An evaluation of Fortify's software security assurance (SSA) solutions in context of the cumulative impact of software security vulnerabilities and the investments made to address them. Read IANS' assessment and key insights from end users in real-world enterprise software development environments.