# Malware **Malware** - **Mal**icious Soft**ware** - A very general term, malware is usually categorised based on - How it proliferates - What it does ![1646673601.png](img/1646673601.png) **Rootkit** - backdoor that installs itself in the kernel which makes it undetectable ### Vectors - Vectors are the mechanism through which malware infects a machine - Usually the vector will be a *software vulnerability* - Or someone clicked something they shouldn’t have ### Payload - Payloads are the actual malware deposited on the machine, or the harmful results - They range in severity - Essentially do nothing - Messages and adverts - Recruited into botnets or mail spam - Stealing private information - System destruction - Ransomware & Crypto-jacking #### Virus - A piece of self-replicating code - Propagates by attaching itself to a disk, file or document - When the file is run, the virus runs and attempts to proliferate - Installs without the users knowledge or consent ##### Notable Viruses - 1981: `Elk Cloner`, the first known virus found *in the wild* that affected Apple II computers - 1986: `Brain`, the first MS-DOS computer virus - 1989: `Ghostball`, the first multipartite virus - affects both `exe`s and the boot sector - 1995: First macro virus, `Concept`, affects MS Word documents - 1996: First linux virus, `Staog`, uses bugs in the linux kernel #### Worms - Viruses traditionally require a human to spread - Worms are self-replicating and stand-alone programs - Do not require human intervention - Scanning worms or email worms - Exploit known software vulnerabilities in order to spread ##### Notable Worms - 1988: The Morris Worm, affects BSD unix machines. One of the first known buffer overruns - 2000: The `ILOVEYOU` worm, one of the most damaging worms ever, used social engineering to get people to install it. - Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as windows didn’t show the file type in the file name ![1646674683.png](img/1646674683.png) ### 2003-2004 - During 2003 and 2004 worms were everywhere - SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet) - Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network - MS Blaster - Windows XP mainly, crashes RPC and reboots your machine - Spreading between machines on a internal network easily, no port filtering - Used a buffer overflow in a windows Remote Procedure Call (RPC) service - spreads without the user clicking - Compromised machines performed DDOS on `windowsupdate.com` - Netsky - Infected email attachment, actually removed other worms as part of a *worm war* - Sasser - From the author of Netsky, attacks windows `LSASS` - Spread 17 days after a patch to the vulnerability was released by Microsoft - Buffer overflow in the Local Security and Authority Subsystem Service `LSASS` - Scans IP addresses and infects via port 445 #### Exploit Life Cycle - Many exploits are reverse engineered from patches, or developed simultaneously to patches ![1646675422.png](img/1646675422.png) ##### Zero-day Exploits - An exploit that is previously unknown - by far the most dangerous ![1646675515.png](img/1646675515.png) ###### Stuxnet - Believed to be an American-Israeli cyber weapon 1. Uses *four zero-day flaws* to infect Windows 2. Seeks out any instance of `Siemens Step7` 3. Finds programmable logic controllers (PLC) 4. Detects attached centrifuges and spins them to destruction 5. Reports that the centrifuges are fine ### Trojans - A malicious program pretending to be a legitimate application - Often obtained in email attachments or at malicious websites - Don’t replicated themselves - *user error* - Randomware is the most common form of Trojan now #### Notable Trojans - 1989: The AIDS Trojan, encrypts all files filenames on the system and request random - 2002: Beast, affects windows machines from 95-XP and provides the attack with a remote admin tool (RAT) - there are a lot of these types - 2013: Cryptolocker - massive randomware ##### Ransomware - Will usually encrypt or block access to files and demand ransom - It is a clever solution, because if an anti-virus removes it, it is often too late - Usually distributed on malicious websites, or to already infected machines - The file decryption keys are protected by encrpyting using the *public key of a C&C server* ###### Ransomware Variants - Most the challenge in successfully using randomware is tricking a user into running it, and bypassing anti-virus and browser protection - Fake emails - Malicious web pages - Obfuscated javascript attachments - Deployed using *exploit kits* ##### CryptoWall JS Example ![1646676226.png](img/1646676226.png) - Everything is obfuscated #### Crypto-jacking - Coinhive is a Monero mining API released in September 2017 - It is a legitimate company, with an aim of replacing advertising on websites with currency mining ![1646676407.png](img/1646676407.png) - This was exploited almost immediately - Extremely easy to use the API - Monero mining is pretty easy even on a CPU - JavaScript is easy to inject onto websites via adverts