Stuxnet Traffic Detection

info Nessus Network Monitor Plugin ID 5721

Synopsis

The remote host is passing RPC traffic which is requesting an RPC UUID which is synonymous with the Stuxnet trojan.

Description

The remote host is passing RPC traffic which is requesting an RPC UUID which is synonymous with the Stuxnet trojan. This may indicate that either the host is infected with Stuxnet or the host is scanning for Stuxnet-infected machines.

Solution

Ensure that the system is not infected. If it is not infected, ensure that the system is authorized to be running security scans on the network.

Plugin Details

Severity: Info

ID: 5721

Family: Backdoors

Published: 12/6/2010

Updated: 6/1/2015

Vulnerability Information

Vulnerability Publication Date: 7/1/2010