This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+43 -43
View File
@@ -3,8 +3,8 @@
**Malware** - **Mal**icious Soft**ware**
- A very general term, malware is usually categorised based on
- How it proliferates
- What it does
- How it proliferates
- What it does
![1646673601.png](img/1646673601.png)
@@ -20,19 +20,19 @@
- Payloads are the actual malware deposited on the machine, or the harmful results
- They range in severity
- Essentially do nothing
- Messages and adverts
- Recruited into botnets or mail spam
- Stealing private information
- System destruction
- Ransomware & Crypto-jacking
- Essentially do nothing
- Messages and adverts
- Recruited into botnets or mail spam
- Stealing private information
- System destruction
- Ransomware & Crypto-jacking
#### Virus
- A piece of self-replicating code
- Propagates by attaching itself to a disk, file or document
- When the file is run, the virus runs and attempts to proliferate
- Installs without the users knowledge or consent
- Installs without the user’s knowledge or consent
##### Notable Viruses
@@ -40,38 +40,38 @@
- 1986: `Brain`, the first MS-DOS computer virus
- 1989: `Ghostball`, the first multipartite virus - affects both `exe`s and the boot sector
- 1995: First macro virus, `Concept`, affects MS Word documents
- 1996: First linux virus, `Staog`, uses bugs in the linux kernel
- 1996: First Linux virus, `Staog`, uses bugs in the Linux kernel
#### Worms
- Viruses traditionally require a human to spread
- Worms are self-replicating and stand-alone programs
- Do not require human intervention
- Do not require human intervention
- Scanning worms or email worms
- Exploit known software vulnerabilities in order to spread
##### Notable Worms
- 1988: The Morris Worm, affects BSD unix machines. One of the first known buffer overruns
- 1988: The Morris Worm, affects BSD Unix machines. One of the first known buffer overruns
- 2000: The `ILOVEYOU` worm, one of the most damaging worms ever, used social engineering to get people to install it.
- Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as windows didn’t show the file type in the file name
- Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as Windows didn’t show the file type in the file name
![1646674683.png](img/1646674683.png)
### 2003-2004
- During 2003 and 2004 worms were everywhere
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
- Spreading between machines on a internal network easily, no port filtering
- Used a buffer overflow in a windows Remote Procedure Call (RPC) service - spreads without the user clicking
- Compromised machines performed DDOS on `windowsupdate.com`
- Netsky - Infected email attachment, actually removed other worms as part of a *worm war*
- Sasser - From the author of Netsky, attacks windows `LSASS`
- Spread 17 days after a patch to the vulnerability was released by Microsoft
- Buffer overflow in the Local Security and Authority Subsystem Service `LSASS`
- Scans IP addresses and infects via port 445
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
- Spreading between machines on an internal network easily, no port filtering
- Used a buffer overflow in a Windows Remote Procedure Call (RPC) service - spreads without the user clicking
- Compromised machines performed DDOS on `windowsupdate.com`
- Netsky - Infected email attachment, actually removed other worms as part of a *worm war*
- Sasser - From the author of Netsky, attacks Windows `LSASS`
- Spread 17 days after a patch to the vulnerability was released by Microsoft
- Buffer overflow in the Local Security and Authority Subsystem Service `LSASS`
- Scans IP addresses and infects via port 445
#### Exploit Life Cycle
@@ -88,39 +88,39 @@
###### Stuxnet
- Believed to be an American-Israeli cyber weapon
1. Uses *four zero-day flaws* to infect Windows
2. Seeks out any instance of `Siemens Step7`
3. Finds programmable logic controllers (PLC)
4. Detects attached centrifuges and spins them to destruction
5. Reports that the centrifuges are fine
1. Uses *four zero-day flaws* to infect Windows
2. Seeks out any instance of `Siemens Step7`
3. Finds programmable logic controllers (PLC)
4. Detects attached centrifuges and spins them to destruction
5. Reports that the centrifuges are fine
### Trojans
- A malicious program pretending to be a legitimate application
- Often obtained in email attachments or at malicious websites
- Don’t replicated themselves - *user error*
- Randomware is the most common form of Trojan now
- Don’t replicate themselves - *user error*
- Ransomware is the most common form of Trojan now
#### Notable Trojans
- 1989: The AIDS Trojan, encrypts all files filenames on the system and request random
- 2002: Beast, affects windows machines from 95-XP and provides the attack with a remote admin tool (RAT) - there are a lot of these types
- 2013: Cryptolocker - massive randomware
- 1989: The AIDS Trojan, encrypts all files’ filenames on the system and requests ransom
- 2002: Beast, affects Windows machines from 95-XP and provides the attacker with a remote admin tool (RAT) - there are a lot of these types
- 2013: Cryptolocker - massive ransomware
##### Ransomware
- Will usually encrypt or block access to files and demand ransom
- It is a clever solution, because if an anti-virus removes it, it is often too late
- Usually distributed on malicious websites, or to already infected machines
- The file decryption keys are protected by encrpyting using the *public key of a C&C server*
- The file decryption keys are protected by encrypting using the *public key of a C&C server*
###### Ransomware Variants
- Most the challenge in successfully using randomware is tricking a user into running it, and bypassing anti-virus and browser protection
- Fake emails
- Malicious web pages
- Obfuscated javascript attachments
- Deployed using *exploit kits*
- Most of the challenge in successfully using ransomware is tricking a user into running it, and bypassing anti-virus and browser protection
- Fake emails
- Malicious web pages
- Obfuscated JavaScript attachments
- Deployed using *exploit kits*
##### CryptoWall JS Example
@@ -136,6 +136,6 @@
![1646676407.png](img/1646676407.png)
- This was exploited almost immediately
- Extremely easy to use the API
- Monero mining is pretty easy even on a CPU
- JavaScript is easy to inject onto websites via adverts
- Extremely easy to use the API
- Monero mining is pretty easy even on a CPU
- JavaScript is easy to inject onto websites via adverts