Duqu contains a backdoor that steals information. Infostealers need to send the stolen info back somehow. Careful infostealers try to make the transfer look innocent in case somebody is watching network traffic. Duqu hides it’s traffic by making it look like normal web traffic. Duqu connects to a server (206.183.111.97 aka canoyragomez.rapidns.com, which used to […]
Latest Comments