MiniDuke - Even Older than we Thought

Bitdefender antimalware researchers have found yet another sample of the MiniDuke malware, only this one is dated June 20, 2011, the oldest found so far.

The malware sample is a small executable that drops and loads a .dll. The dll is a little bit different from more recent versions, it has many imports, just as if it was an ordinary program,  from kernel32.dll, user32.dll, gdi32.dll and comctl32.dll. Also, the method of computing the system fingerprint is a little different.

Interestingly, the current time/date was then fetched from tycho.usno.navy.mil/cgi-bin/timer.pl (Department of the Navy site).

There is no Google search backup way to contact command and control servers (if connecting to Twitter fails, then nothing happens). So we can see that the use of Google search technique has been introduced after 2011.

There are also new (to us) Twitter indicatives: ObamaApril and Qae9XMs. In this earlier version the malware connects to twitter.com directly, instead of via mobile.twitter.com as in 2012/2013 versions.

Surprisingly enough, the Twitter account which was used is still active. Its last and single post is from Feb 21, 2012. tweet is uri!wp07VkkxYt3Ag/bdbNgi3smPJvX7+HLEw5H6/S0RsmHKtA== and this decodes to “http://afgcall.com/demo/index.php”, another server that was probably hacked. However, no files have been found on that particular server. This is probably because the malware sample is so old that the command and control server is no longer active.

A removal tool covering all known variants (including this one) has been posted here:

MiniDuke Removal Tool (4043)

9 Responses to MiniDuke – Even Older than we Thought


  1. Marmota says:

    index.php was deleted, but is possible a file listing to /demo/, amatori:))
    Data/ 18-Jan-2013 16:33 –
    banner.swf 13-Aug-2012 09:09 267K
    php/ 18-Jan-2013 16:33 -

  2. mtivadar says:

    Indeed, but /demo/ could belong to the original site.

  3. Chris says:

    Some details on what it does such as install hidden network adaptor and run its own hidden network from it would be helpful. I beleive it has also modified my bios cmos.

Leave a Reply

Your email address will not be published. Required fields are marked *