Files
2026-10-04 15:24:17 +01:00

5.2 KiB
Raw Permalink Blame History

Malware

Malware - Malicious Software

  • A very general term, malware is usually categorised based on
    • How it proliferates
    • What it does

1646673601.png

Rootkit - backdoor that installs itself in the kernel which makes it undetectable

Vectors

  • Vectors are the mechanism through which malware infects a machine
  • Usually the vector will be a software vulnerability
  • Or someone clicked something they shouldn’t have

Payload

  • Payloads are the actual malware deposited on the machine, or the harmful results
  • They range in severity
    • Essentially do nothing
    • Messages and adverts
    • Recruited into botnets or mail spam
    • Stealing private information
    • System destruction
    • Ransomware & Crypto-jacking

Virus

  • A piece of self-replicating code
  • Propagates by attaching itself to a disk, file or document
  • When the file is run, the virus runs and attempts to proliferate
  • Installs without the user’s knowledge or consent
Notable Viruses
  • 1981: Elk Cloner, the first known virus found in the wild that affected Apple II computers
  • 1986: Brain, the first MS-DOS computer virus
  • 1989: Ghostball, the first multipartite virus - affects both exes and the boot sector
  • 1995: First macro virus, Concept, affects MS Word documents
  • 1996: First Linux virus, Staog, uses bugs in the Linux kernel

Worms

  • Viruses traditionally require a human to spread
  • Worms are self-replicating and stand-alone programs
    • Do not require human intervention
  • Scanning worms or email worms
  • Exploit known software vulnerabilities in order to spread
Notable Worms
  • 1988: The Morris Worm, affects BSD Unix machines. One of the first known buffer overruns
  • 2000: The ILOVEYOU worm, one of the most damaging worms ever, used social engineering to get people to install it.
    • Used the file name LOVE-LETTER-FOR-YOU.txt.vbs as Windows didn’t show the file type in the file name

1646674683.png

2003-2004

  • During 2003 and 2004 worms were everywhere
    • SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
      • Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
    • MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
      • Spreading between machines on an internal network easily, no port filtering
      • Used a buffer overflow in a Windows Remote Procedure Call (RPC) service - spreads without the user clicking
      • Compromised machines performed DDOS on windowsupdate.com
    • Netsky - Infected email attachment, actually removed other worms as part of a worm war
    • Sasser - From the author of Netsky, attacks Windows LSASS
      • Spread 17 days after a patch to the vulnerability was released by Microsoft
      • Buffer overflow in the Local Security and Authority Subsystem Service LSASS
      • Scans IP addresses and infects via port 445

Exploit Life Cycle

  • Many exploits are reverse engineered from patches, or developed simultaneously to patches

1646675422.png

Zero-day Exploits
  • An exploit that is previously unknown - by far the most dangerous

1646675515.png

Stuxnet
  • Believed to be an American-Israeli cyber weapon
    1. Uses four zero-day flaws to infect Windows
    2. Seeks out any instance of Siemens Step7
    3. Finds programmable logic controllers (PLC)
    4. Detects attached centrifuges and spins them to destruction
    5. Reports that the centrifuges are fine

Trojans

  • A malicious program pretending to be a legitimate application
  • Often obtained in email attachments or at malicious websites
  • Don’t replicate themselves - user error
  • Ransomware is the most common form of Trojan now

Notable Trojans

  • 1989: The AIDS Trojan, encrypts all files’ filenames on the system and requests ransom
  • 2002: Beast, affects Windows machines from 95-XP and provides the attacker with a remote admin tool (RAT) - there are a lot of these types
  • 2013: Cryptolocker - massive ransomware
Ransomware
  • Will usually encrypt or block access to files and demand ransom
  • It is a clever solution, because if an anti-virus removes it, it is often too late
  • Usually distributed on malicious websites, or to already infected machines
  • The file decryption keys are protected by encrypting using the public key of a C&C server
Ransomware Variants
  • Most of the challenge in successfully using ransomware is tricking a user into running it, and bypassing anti-virus and browser protection
    • Fake emails
    • Malicious web pages
    • Obfuscated JavaScript attachments
    • Deployed using exploit kits
CryptoWall JS Example

1646676226.png

  • Everything is obfuscated

Crypto-jacking

  • Coinhive is a Monero mining API released in September 2017
  • It is a legitimate company, with an aim of replacing advertising on websites with currency mining

1646676407.png

  • This was exploited almost immediately
    • Extremely easy to use the API
    • Monero mining is pretty easy even on a CPU
    • JavaScript is easy to inject onto websites via adverts