【文章标题】:Show HN: Stuxnet – A reconstructed source code of the infamous cyber-weapon 【文章标题】:展示HN:震网病毒——臭名昭著的网络武器源代码重构

【文章正文】: This repository contains a strictly educational and research-oriented reconstruction of the infamous Stuxnet worm. It is the product of countless hours of reverse engineering work conducted by the global security research community on the original binary samples discovered in 2010. 【文章正文】: 本代码库包含严格用于教育研究目的的震网病毒重构版本。这是全球安全研究社区对2010年发现的原始二进制样本进行数千小时逆向工程工作的成果。

Disclaimer: This code is provided solely for academic study, malware analysis training, and defensive research. It is not intended to be used for any malicious purposes, nor is it a deployable piece of malware. The authors and contributors do not condone illegal or unethical activities. 免责声明:本代码仅用于学术研究、恶意软件分析培训和防御性研究。不可用于任何恶意目的,也不具备实际部署的恶意软件功能。作者与贡献者不认可任何非法或不道德行为。

Table of Contents 目录 Overview 概述 Core Components 核心组件 Technical Architecture 技术架构 Build Instructions 构建说明 Usage 使用说明 Legal and License 法律与许可 Acknowledgements 致谢

Stuxnet is widely recognized as the first known cyber-weapon designed to cause physical destruction to industrial control systems (ICS). It specifically targeted Siemens Step 7 software and S7-300/400 PLCs, ultimately manipulating frequency converter drives to damage centrifuge rotors. 震网病毒被公认为首个旨在破坏工业控制系统(ICS)的网络武器。它专门针对西门子Step 7软件和S7-300/400 PLC,通过操控变频驱动器来破坏离心机转子。

This repository is a reconstructed source code derived from the decompiled binaries. It preserves the original logic and attack vectors while structuring the codebase for readability and analysis. 本代码库是从反编译二进制文件重构的源代码,在保持原始逻辑和攻击向量的同时,优化了代码结构以提高可读性和可分析性。

Key Characteristics 关键特征 Target: Siemens SIMATIC WinCC, Step 7, and S7 PLCs. 目标:西门子SIMATIC WinCC、Step 7及S7 PLC Propagation: USB drives (LNK exploits), Network shares (Print Spooler), Peer-to-Peer (P2P). 传播方式:U盘(LNK漏洞)、网络共享(打印后台程序)、点对点(P2P) Payload: Modification of PLC block logic (OB1/OB35) to alter motor frequencies. 有效载荷:修改PLC块逻辑(OB1/OB35)以改变电机频率 Stealth: Advanced Rootkit capabilities (MRxCls.sys, MRxNet.sys) for file, process, and registry hiding. 隐蔽性:具备高级Rootkit功能(MRxCls.sys, MRxNet.sys)用于隐藏文件、进程和注册表

The repository is organized by the primary modules identified during the analysis of the original malware. 代码库按原始恶意软件分析确定的主要模块进行组织。

Module: Loader/Dropper Filename: winsta.exe, ~WTR4141.tmp Description: Entry point responsible for initial infection, privilege escalation, and deployment of other components. 模块:加载器/投放器 文件名:winsta.exe, ~WTR4141.tmp 描述:负责初始感染、权限提升和其他组件部署的入口点

Module: Privilege Escalation Filename: ~WTR4132.tmp Description: Exploits the Win32k.sys vulnerability to gain system-level privileges. 模块:权限提升 文件名:~WTR4132.tmp 描述:利用Win32k.sys漏洞获取系统级权限

Module: S7 Hook Library Filename: s7otbxdx.dll Description: Malicious replacement of the original s7otbxsx.dll. Intercepts communication between Step 7 and the PLC. 模块:S7钩子库 文件名:s7otbxdx.dll 描述:恶意替换原s7otbxsx.dll,拦截Step 7与PLC间通信

Module: Step7 Hook Library Filename: s7aaapix.dll Description: Intercepts AUT (Automation Tool) API calls within the Step 7 engineering environment. 模块:Step7钩子库 文件名:s7aaapix.dll 描述:拦截Step 7工程环境中的AUT(自动化工具)API调用

Module: Rootkit (File System) Filename: mrxcls.sys Description: Kernel-mode driver used to hide Stuxnet files, processes, and registry keys via SSDT hooking. 模块:Rootkit(文件系统) 文件名:mrxcls.sys 描述:通过SSDT挂钩隐藏震网文件、进程和注册表键的内核模式驱动

Module: Rootkit (Network) Filename: mrxnet.sys Description: Filters file system requests to hide malicious files and enables P2P propagation. 模块:Rootkit(网络) 文件名:mrxnet.sys 描述:过滤文件系统请求以隐藏恶意文件并启用P2P传播

Module: Payload (Attack) Filename: s7plcmain Description: The core logic responsible for the “Frequency Tampering” attack that damages the centrifuges. 模块:有效载荷(攻击) 文件名:s7plcmain 描述:实施”频率篡改”攻击破坏离心机的核心逻辑

The following describes the high-level execution flow of the Stuxnet framework. 以下描述震网框架的高层执行流程。

Stage 1: Initial Infection Vector (USB/Network) Stage 2: Dropper and Escalation Stage 3: Check Environment Stage 4a: Target Found (Siemens Software) -> Install S7 Hooks Stage 4b: Non-target -> Self-Destruct/Idle Stage 5: Monitor PLC Writes Stage 6: Detect OB1/OB35 Write -> Inject Payload Stage 7: Modify Frequency Output Stage 8: Physical Damage to Centrifuges Stage 9: Install Rootkit (MRxCls) Stage 10: Hide Files and Registry Stage 11: Load Network Module (MRxNet) Stage 12: P2P Propagation 阶段1:初始感染载体(U盘/网络) 阶段2:投放器与权限提升 阶段3:环境检测 阶段4a:发现目标(西门子软件)->安装S7钩子 阶段4b:非目标->自毁/待机 阶段5:监控PLC写入 阶段6:检测OB1/OB35写入->注入有效载荷 阶段7:修改频率输出 阶段8:离心机物理损坏 阶段9:安装Rootkit(MRxCls) 阶段10:隐藏文件与注册表 阶段11:加载网络模块(MRxNet) 阶段12:P2P传播

Execution Flow 执行流程

Environment Reconnaissance: The worm checks for the presence of specific Siemens software (WinCC, Step 7) and specific target PLCs (S7-315, S7-417). 环境侦察:蠕虫检查特定西门子软件(WinCC, Step 7)和目标PLC(S7-315, S7-417)是否存在

DLL Injection: It intercepts the s7blk_write function call. DLL注入:拦截s7blk_write函数调用

Code Injection: When a user downloads a project to the PLC, the malicious code is appended to the OB1/OB35 blocks. 代码注入:当用户下载项目到PLC时,恶意代码被附加到OB1/OB35块

Physical Impact: The PLC executes the manipulated code, causing the connected variable frequency drives (VFDs) to spin at abnormal frequencies (high/low), resulting in mechanical damage. 物理影响:PLC执行被篡改的代码,导致连接的变频驱动器(VFD)以异常频率(高/低)旋转,造成机械损坏

Build Instructions 构建说明 Important: This codebase is designed for static analysis and debugging in a controlled virtual environment. It is not intended for live deployment on any critical infrastructure. 重要提示:本代码库设计用于受控虚拟环境中的静态分析和调试,不可部署于任何关键基础设施。

Requirements 需求 Build Environment: Microsoft Visual Studio 2019/2022 (Windows) or mingw-w64. 构建环境:Microsoft Visual Studio 2019/2022(Windows)或mingw-w64 Target OS: Windows XP / Windows 7 (for driver compatibility). 目标系统:Windows XP/Windows 7(确保驱动兼容性) Driver Kit: Windows Driver Kit (WDK) 7600 (if compiling kernel drivers). 驱动工具包:Windows Driver Kit (WDK) 7600(如需编译内核驱动)

Building the User-Mode Modules 构建用户模式模块 Clone the repository 克隆代码库 git clone https://github.com/Sadpainy/Stuxnet.git cd stuxnet-analysis Build the main dropper 构建主投放器 cd winsta nmake /f Makefile.win Build the S7 hook library 构建S7钩子库 cd ../s7otbxdx cl /LD s7otbxdx.c user32.lib ws2_32.lib

This code is intended for: 本代码适用于: Malware Analysis: Understanding the specific code logic used in advanced persistent threats (APTs). 恶意软件分析:理解高级持续性威胁(APT)使用的特定代码逻辑 Defensive Research: Developing detection signatures for ICS security tools (e.g., YARA rules, Snort signatures). 防御研究:开发ICS安全工具的检测特征(如YARA规则、Snort特征) Academic Study: Examining the intersection of cybersecurity and critical infrastructure protection. 学术研究:探讨网络安全与关键基础设施保护的交叉领域

Analysis Setup 分析设置

Isolate Environment: Use a virtual machine 隔离环境:使用虚拟机