5.2 KiB
5.2 KiB
Malware
Malware - Malicious Software
- A very general term, malware is usually categorised based on
- How it proliferates
- What it does
Rootkit - backdoor that installs itself in the kernel which makes it undetectable
Vectors
- Vectors are the mechanism through which malware infects a machine
- Usually the vector will be a software vulnerability
- Or someone clicked something they shouldn’t have
Payload
- Payloads are the actual malware deposited on the machine, or the harmful results
- They range in severity
- Essentially do nothing
- Messages and adverts
- Recruited into botnets or mail spam
- Stealing private information
- System destruction
- Ransomware & Crypto-jacking
Virus
- A piece of self-replicating code
- Propagates by attaching itself to a disk, file or document
- When the file is run, the virus runs and attempts to proliferate
- Installs without the user’s knowledge or consent
Notable Viruses
- 1981:
Elk Cloner, the first known virus found in the wild that affected Apple II computers - 1986:
Brain, the first MS-DOS computer virus - 1989:
Ghostball, the first multipartite virus - affects bothexes and the boot sector - 1995: First macro virus,
Concept, affects MS Word documents - 1996: First Linux virus,
Staog, uses bugs in the Linux kernel
Worms
- Viruses traditionally require a human to spread
- Worms are self-replicating and stand-alone programs
- Do not require human intervention
- Scanning worms or email worms
- Exploit known software vulnerabilities in order to spread
Notable Worms
- 1988: The Morris Worm, affects BSD Unix machines. One of the first known buffer overruns
- 2000: The
ILOVEYOUworm, one of the most damaging worms ever, used social engineering to get people to install it.- Used the file name
LOVE-LETTER-FOR-YOU.txt.vbsas Windows didn’t show the file type in the file name
- Used the file name
2003-2004
- During 2003 and 2004 worms were everywhere
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
- Spreading between machines on an internal network easily, no port filtering
- Used a buffer overflow in a Windows Remote Procedure Call (RPC) service - spreads without the user clicking
- Compromised machines performed DDOS on
windowsupdate.com
- Netsky - Infected email attachment, actually removed other worms as part of a worm war
- Sasser - From the author of Netsky, attacks Windows
LSASS- Spread 17 days after a patch to the vulnerability was released by Microsoft
- Buffer overflow in the Local Security and Authority Subsystem Service
LSASS - Scans IP addresses and infects via port 445
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
Exploit Life Cycle
- Many exploits are reverse engineered from patches, or developed simultaneously to patches
Zero-day Exploits
- An exploit that is previously unknown - by far the most dangerous
Stuxnet
- Believed to be an American-Israeli cyber weapon
- Uses four zero-day flaws to infect Windows
- Seeks out any instance of
Siemens Step7 - Finds programmable logic controllers (PLC)
- Detects attached centrifuges and spins them to destruction
- Reports that the centrifuges are fine
Trojans
- A malicious program pretending to be a legitimate application
- Often obtained in email attachments or at malicious websites
- Don’t replicate themselves - user error
- Ransomware is the most common form of Trojan now
Notable Trojans
- 1989: The AIDS Trojan, encrypts all files’ filenames on the system and requests ransom
- 2002: Beast, affects Windows machines from 95-XP and provides the attacker with a remote admin tool (RAT) - there are a lot of these types
- 2013: Cryptolocker - massive ransomware
Ransomware
- Will usually encrypt or block access to files and demand ransom
- It is a clever solution, because if an anti-virus removes it, it is often too late
- Usually distributed on malicious websites, or to already infected machines
- The file decryption keys are protected by encrypting using the public key of a C&C server
Ransomware Variants
- Most of the challenge in successfully using ransomware is tricking a user into running it, and bypassing anti-virus and browser protection
- Fake emails
- Malicious web pages
- Obfuscated JavaScript attachments
- Deployed using exploit kits
CryptoWall JS Example
- Everything is obfuscated
Crypto-jacking
- Coinhive is a Monero mining API released in September 2017
- It is a legitimate company, with an aim of replacing advertising on websites with currency mining
- This was exploited almost immediately
- Extremely easy to use the API
- Monero mining is pretty easy even on a CPU
- JavaScript is easy to inject onto websites via adverts





