metasploit-framework/modules/post/windows/gather/forensics/duqu_check.rb

82 lines
2.5 KiB
Ruby
Raw Normal View History

2011-11-10 21:20:48 +00:00
##
# ## This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
2011-11-10 21:20:48 +00:00
##
require 'msf/core'
require 'msf/core/post/common'
2012-06-27 05:47:22 +00:00
require 'msf/core/post/windows/registry'
2011-11-10 21:20:48 +00:00
require 'msf/core/post/windows/priv'
2012-10-23 18:24:05 +00:00
require 'msf/core/auxiliary/report'
2011-11-10 21:20:48 +00:00
class Metasploit3 < Msf::Post
include Msf::Post::Common
include Msf::Post::Windows::Registry
include Msf::Auxiliary::Report
2011-11-10 21:20:48 +00:00
def initialize(info={})
super( update_info( info,
2012-04-19 01:45:25 +00:00
'Name' => 'Windows Gather Forensics Duqu Registry Check',
2011-11-17 13:47:26 +00:00
'Description' => %q{ This module searches for CVE-2011-3402 (Duqu) related registry artifacts.},
'License' => MSF_LICENSE,
'Author' => [ 'Marcus J. Carey <mjc[at]threatagent.com>'],
'Platform' => [ 'win' ],
'SessionTypes' => [ 'meterpreter' ],
'References' =>
[
[ 'CVE', '2011-3402' ],
[ 'URL', 'http://r-7.co/w5h7fY' ]
]
))
end
2011-11-10 21:20:48 +00:00
def run
# Registry artifacts sourced from Symantec report
artifacts =
[
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\"CFID"',
'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\CFID',
'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JmiNET3',
'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\JmiNET3\FILTER'
]
match = 0
print_status("Searching registry on #{sysinfo['Computer']} for CVE-2011-3402 exploitation [Duqu] artifacts.")
begin
artifacts.each do |artifact|
(path, query) = parse_path(artifact)
has_key = registry_enumkeys(path)
has_val = registry_enumvals(path)
2011-11-10 21:20:48 +00:00
if has_key.include?(query) or has_val.include?(query)
print_good("#{sysinfo['Computer']}: #{path}\\#{query} found in registry.")
match += 1
report_vuln(
:host => session.session_host,
:name => self.name,
:info => "Module #{self.fullname} detected #{path}\\#{query} - possible CVE-2011-3402 exploitation [Duqu] artifact.",
:refs => self.references,
2012-07-02 19:15:14 +00:00
:exploited_at => Time.now.utc
)
end
2011-11-10 21:20:48 +00:00
end
rescue # Probably should do something here...
end
print_status("#{sysinfo['Computer']}: #{match.to_s} artifact(s) found in registry.")
2011-11-10 21:20:48 +00:00
end
2011-11-10 21:20:48 +00:00
def parse_path(artifact)
parts = artifact.split("\\")
query = parts[-1]
parts.pop
path = parts.join("\\")
return path, query
2011-11-10 21:20:48 +00:00
end
2011-11-11 15:44:18 +00:00
end