Click here to Skip to main content
15,896,557 members
Please Sign up or sign in to vote.
0.00/5 (No votes)
Hello, Everyone

I have taken an interest in the Stuxnet virus. I was reading about it and I wondered how Symantec extracted information from the compiled executable. Does a compiler for Windows .exe's embed information about the developer in it? Say the developer PC's name is 'Jim-PC' and the account is 'Jim', does the compiler (Visual Studio 2008 for instance) embed that info into the .exe? Are there small references in the .exe about the developer? (Apart from assembly info, of course)
Posted

1 solution

The only thing they had from the Stuxnet binary was a dll with a specific build time-stamp on it. Obviously that could easily have been faked. Other than that they use originating IPs and early detections to try and trace out from where the infection may have originated. There is a lot of social reverse engineering based research and parsing of ISP logs. And then again, a lot of it is speculation too.
 
Share this answer
 

This content, along with any associated source code and files, is licensed under The Code Project Open License (CPOL)



CodeProject, 20 Bay Street, 11th Floor Toronto, Ontario, Canada M5J 2N8 +1 (416) 849-8900