Interesting artifact in Stuxnet: guava.pdb

Discussion in 'Serious Discussion' started by lakrispipe, Jan 21, 2020.

  1. lakrispipe

    lakrispipe MDL Novice

    Joined:
    Oct 12, 2019
    Messages:
    5
    Likes Received:
    14
    Trophy Points:
    0
    Looking at the source code for Stuxnet you can find this interesting path: b:\myrtus\src\objfre_w2k_x86\i386\guava.pdb

    I've read different theories on what this means and the most common ones are summarized on wikipedia:

    In the wikipedia article for guava it says:

    Any alternative theories on why the malware authors chose to name it guava? Very interesting for sure :)
     
  2. Yen

    Yen Admin Staff Member

    Joined:
    May 6, 2007
    Messages:
    12,431
    Likes Received:
    12,999
    Trophy Points:
    340
    The relation Guava to Myrtus is botanically reasonable.
    Guava (Psidium guajava) belongs to the family of Myrtaceae and the order of Myrtales.
    (We once researched about Psidium leaves to develop meds against diarrhea...)....

    Myrtle (Myrtus communis) belongs also to the family of Myrtaceae and the order of Myrtales.
    Both plants are botanically related, means 'Myrtus and Guava' are botanically related, they have the same family.

    The relation to 'Esther' is far fetched.
    If you want to have a biblical relation then rather have a look what's the role of Myrtle there. (For instance the transformation of Nature).

    TBH the relation to My RTUs as a hint to RemoteTerminalUnit seems to be more reasonable....