Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -3,8 +3,8 @@
|
||||
**Malware** - **Mal**icious Soft**ware**
|
||||
|
||||
- A very general term, malware is usually categorised based on
|
||||
- How it proliferates
|
||||
- What it does
|
||||
- How it proliferates
|
||||
- What it does
|
||||
|
||||

|
||||
|
||||
@@ -20,19 +20,19 @@
|
||||
|
||||
- Payloads are the actual malware deposited on the machine, or the harmful results
|
||||
- They range in severity
|
||||
- Essentially do nothing
|
||||
- Messages and adverts
|
||||
- Recruited into botnets or mail spam
|
||||
- Stealing private information
|
||||
- System destruction
|
||||
- Ransomware & Crypto-jacking
|
||||
- Essentially do nothing
|
||||
- Messages and adverts
|
||||
- Recruited into botnets or mail spam
|
||||
- Stealing private information
|
||||
- System destruction
|
||||
- Ransomware & Crypto-jacking
|
||||
|
||||
#### Virus
|
||||
|
||||
- A piece of self-replicating code
|
||||
- Propagates by attaching itself to a disk, file or document
|
||||
- When the file is run, the virus runs and attempts to proliferate
|
||||
- Installs without the users knowledge or consent
|
||||
- Installs without the user’s knowledge or consent
|
||||
|
||||
##### Notable Viruses
|
||||
|
||||
@@ -40,38 +40,38 @@
|
||||
- 1986: `Brain`, the first MS-DOS computer virus
|
||||
- 1989: `Ghostball`, the first multipartite virus - affects both `exe`s and the boot sector
|
||||
- 1995: First macro virus, `Concept`, affects MS Word documents
|
||||
- 1996: First linux virus, `Staog`, uses bugs in the linux kernel
|
||||
- 1996: First Linux virus, `Staog`, uses bugs in the Linux kernel
|
||||
|
||||
#### Worms
|
||||
|
||||
- Viruses traditionally require a human to spread
|
||||
- Worms are self-replicating and stand-alone programs
|
||||
- Do not require human intervention
|
||||
- Do not require human intervention
|
||||
- Scanning worms or email worms
|
||||
- Exploit known software vulnerabilities in order to spread
|
||||
|
||||
##### Notable Worms
|
||||
|
||||
- 1988: The Morris Worm, affects BSD unix machines. One of the first known buffer overruns
|
||||
- 1988: The Morris Worm, affects BSD Unix machines. One of the first known buffer overruns
|
||||
- 2000: The `ILOVEYOU` worm, one of the most damaging worms ever, used social engineering to get people to install it.
|
||||
- Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as windows didn’t show the file type in the file name
|
||||
- Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as Windows didn’t show the file type in the file name
|
||||
|
||||

|
||||
|
||||
### 2003-2004
|
||||
|
||||
- During 2003 and 2004 worms were everywhere
|
||||
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
|
||||
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
|
||||
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
|
||||
- Spreading between machines on a internal network easily, no port filtering
|
||||
- Used a buffer overflow in a windows Remote Procedure Call (RPC) service - spreads without the user clicking
|
||||
- Compromised machines performed DDOS on `windowsupdate.com`
|
||||
- Netsky - Infected email attachment, actually removed other worms as part of a *worm war*
|
||||
- Sasser - From the author of Netsky, attacks windows `LSASS`
|
||||
- Spread 17 days after a patch to the vulnerability was released by Microsoft
|
||||
- Buffer overflow in the Local Security and Authority Subsystem Service `LSASS`
|
||||
- Scans IP addresses and infects via port 445
|
||||
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
|
||||
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
|
||||
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
|
||||
- Spreading between machines on an internal network easily, no port filtering
|
||||
- Used a buffer overflow in a Windows Remote Procedure Call (RPC) service - spreads without the user clicking
|
||||
- Compromised machines performed DDOS on `windowsupdate.com`
|
||||
- Netsky - Infected email attachment, actually removed other worms as part of a *worm war*
|
||||
- Sasser - From the author of Netsky, attacks Windows `LSASS`
|
||||
- Spread 17 days after a patch to the vulnerability was released by Microsoft
|
||||
- Buffer overflow in the Local Security and Authority Subsystem Service `LSASS`
|
||||
- Scans IP addresses and infects via port 445
|
||||
|
||||
#### Exploit Life Cycle
|
||||
|
||||
@@ -88,39 +88,39 @@
|
||||
###### Stuxnet
|
||||
|
||||
- Believed to be an American-Israeli cyber weapon
|
||||
1. Uses *four zero-day flaws* to infect Windows
|
||||
2. Seeks out any instance of `Siemens Step7`
|
||||
3. Finds programmable logic controllers (PLC)
|
||||
4. Detects attached centrifuges and spins them to destruction
|
||||
5. Reports that the centrifuges are fine
|
||||
1. Uses *four zero-day flaws* to infect Windows
|
||||
2. Seeks out any instance of `Siemens Step7`
|
||||
3. Finds programmable logic controllers (PLC)
|
||||
4. Detects attached centrifuges and spins them to destruction
|
||||
5. Reports that the centrifuges are fine
|
||||
|
||||
### Trojans
|
||||
|
||||
- A malicious program pretending to be a legitimate application
|
||||
- Often obtained in email attachments or at malicious websites
|
||||
- Don’t replicated themselves - *user error*
|
||||
- Randomware is the most common form of Trojan now
|
||||
- Don’t replicate themselves - *user error*
|
||||
- Ransomware is the most common form of Trojan now
|
||||
|
||||
#### Notable Trojans
|
||||
|
||||
- 1989: The AIDS Trojan, encrypts all files filenames on the system and request random
|
||||
- 2002: Beast, affects windows machines from 95-XP and provides the attack with a remote admin tool (RAT) - there are a lot of these types
|
||||
- 2013: Cryptolocker - massive randomware
|
||||
- 1989: The AIDS Trojan, encrypts all files’ filenames on the system and requests ransom
|
||||
- 2002: Beast, affects Windows machines from 95-XP and provides the attacker with a remote admin tool (RAT) - there are a lot of these types
|
||||
- 2013: Cryptolocker - massive ransomware
|
||||
|
||||
##### Ransomware
|
||||
|
||||
- Will usually encrypt or block access to files and demand ransom
|
||||
- It is a clever solution, because if an anti-virus removes it, it is often too late
|
||||
- Usually distributed on malicious websites, or to already infected machines
|
||||
- The file decryption keys are protected by encrpyting using the *public key of a C&C server*
|
||||
- The file decryption keys are protected by encrypting using the *public key of a C&C server*
|
||||
|
||||
###### Ransomware Variants
|
||||
|
||||
- Most the challenge in successfully using randomware is tricking a user into running it, and bypassing anti-virus and browser protection
|
||||
- Fake emails
|
||||
- Malicious web pages
|
||||
- Obfuscated javascript attachments
|
||||
- Deployed using *exploit kits*
|
||||
- Most of the challenge in successfully using ransomware is tricking a user into running it, and bypassing anti-virus and browser protection
|
||||
- Fake emails
|
||||
- Malicious web pages
|
||||
- Obfuscated JavaScript attachments
|
||||
- Deployed using *exploit kits*
|
||||
|
||||
##### CryptoWall JS Example
|
||||
|
||||
@@ -136,6 +136,6 @@
|
||||

|
||||
|
||||
- This was exploited almost immediately
|
||||
- Extremely easy to use the API
|
||||
- Monero mining is pretty easy even on a CPU
|
||||
- JavaScript is easy to inject onto websites via adverts
|
||||
- Extremely easy to use the API
|
||||
- Monero mining is pretty easy even on a CPU
|
||||
- JavaScript is easy to inject onto websites via adverts
|
||||
Reference in new issue
Block a user