Log in

View Full Version : Amr Thabet: Reversing Stuxnet's Rootkit (MRxNet) Into C++


Silkut
January 30th, 2011, 09:25
Hi,

Everyone interested in malware, malware fighting and reversing noticed the release of a (decompiled) source code from an Egyptian reverser, on the Stuxnet rootkit. It is based on a manual analysis with IDA pro.

Regarding to what is happening to Egypt at this moment, I'm relaying the news and keeping a copy for the library.

I won't get into a political debate over the events, let's just hope he is safe.


http://amrthabet.blogspot.com/2011/01/reversing-stuxnets-rootkit-mrxnet-into.html


MALWARE/BIOHAZARD
for backup purpose
(the driver is flagged by AV, so I put a password on the archive: infected)
2419

OHPen
January 31st, 2011, 10:17
Hi Silkut,

thank you for that submission. It's quite interessting!
Hope your guy is ok.

Regards,
OHPen.

Silkut
January 31st, 2011, 10:47
It's not my guy lol, but yeah no news from the author yet...

OHPen
January 31st, 2011, 10:53
Hey,

was more meant like, "your man from egypt" ! No offense here ;D
And even if it would be "your guy", i really don't mínd )

Hopefully the situation there will calm down soon...

Regards,
"your man from germany",
OHPen ;D

Silkut
February 6th, 2011, 08:19
Posted by the author: http://www.woodmann.com/collaborative/knowledge/Stuxnet's_Rootkit_(MRxNet)_into_C%2B%2B