Kaspersky has already done that - it's looking for a specific registry key. The problem is, they've tried every plausible value they can think of.
Assuming this payload is along the same lines as Stuxnet, I think the answer is pretty obvious: it's looking for a registry key associated with someone's specifically customized SCADA software. The key's probably in some non-English language and has never been seen outside the campus of the target.
Posted Aug 23, 2012 12:51 UTC (Thu) by ekj (guest, #1524)
[Link]
That makes sense. Or the key could be the hash of some executable or something of that order, that the software checks to ensure the integrity of the file - if so that's equivalent to a random number (aslong as you don't have that specific file, I mean)