CVE-2010-2568 (LNK vunerability) Zero Day Stuxnet-A Sample + PoC by Ivanlef0u + Links
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Rootkit - T1014 Rootkit |
Common Information
Type | Value |
---|---|
UUID | 540e6d1d-4ba4-4ffe-b80f-f6d605f92743 |
Fingerprint | 2496a853e483ec97 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 18, 2010, 3:56 p.m. |
Added to db | Jan. 18, 2023, 7:45 p.m. |
Last updated | Nov. 18, 2024, 2:35 a.m. |
Headline | UNKNOWN |
Title | CVE-2010-2568 (LNK vunerability) Zero Day Stuxnet-A Sample + PoC by Ivanlef0u + Links |
Detected Hints/Tags/Attributes | 33/2/23 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 48 | cve-2010-2568 |
|
Details | Domain | 1 | twitpic.com |
|
Details | Domain | 318 | bit.ly |
|
Details | File | 4 | rootkit.tmp |
|
Details | File | 17 | mrxcls.sys |
|
Details | File | 14 | mrxnet.sys |
|
Details | File | 478 | lsass.exe |
|
Details | File | 1 | %windir%\system32\drivers\mrxcls.sys |
|
Details | md5 | 2 | 74ddc49a7c121a61b8d06c03f92d0c13 |
|
Details | md5 | 1 | 016169ebebf1cec2aad6c7f0d0ee9026 |
|
Details | sha256 | 1 | 743e16b3ef4d39fc11c5e8ec890dcd29f034a6eca51be4f7fca6e23e60dbd7a1 |
|
Details | IPv4 | 5 | 5.0.0.31 |
|
Details | IPv4 | 1 | 8.2.4.12 |
|
Details | IPv4 | 10 | 3.1.1.84 |
|
Details | IPv4 | 59 | 7.0.0.125 |
|
Details | IPv4 | 39 | 7.0.3.5 |
|
Details | IPv4 | 9 | 101.1.1.7 |
|
Details | IPv4 | 1 | 3.12.12.6 |
|
Details | IPv4 | 10 | 5.0.27.0 |
|
Details | Url | 1 | http://twitpic.com/24z86b |
|
Details | Url | 1 | http://bit.ly/a1bhaz |
|
Details | Url | 1 | http://www.virustotal.com/analisis/743e16b3ef4d39fc11c5e8ec890dcd29f034a6eca51be4f7fca6e23e60dbd7a1-1279281358 |
|
Details | Windows Registry Key | 1 | HKLM\SYSTEM\CurrentControlSet\Services\MRxCls |