5.1 KiB
5.1 KiB
Malware
Malware - Malicious Software
- A very general term, malware is usually categorised based on
- How it proliferates
- What it does
Rootkit - backdoor that installs itself in the kernel which makes it undetectable
Vectors
- Vectors are the mechanism through which malware infects a machine
- Usually the vector will be a software vulnerability
- Or someone clicked something they shouldn’t have
Payload
- Payloads are the actual malware deposited on the machine, or the harmful results
- They range in severity
- Essentially do nothing
- Messages and adverts
- Recruited into botnets or mail spam
- Stealing private information
- System destruction
- Ransomware & Crypto-jacking
Virus
- A piece of self-replicating code
- Propagates by attaching itself to a disk, file or document
- When the file is run, the virus runs and attempts to proliferate
- Installs without the users knowledge or consent
Notable Viruses
- 1981:
Elk Cloner, the first known virus found in the wild that affected Apple II computers - 1986:
Brain, the first MS-DOS computer virus - 1989:
Ghostball, the first multipartite virus - affects bothexes and the boot sector - 1995: First macro virus,
Concept, affects MS Word documents - 1996: First linux virus,
Staog, uses bugs in the linux kernel
Worms
- Viruses traditionally require a human to spread
- Worms are self-replicating and stand-alone programs
- Do not require human intervention
- Scanning worms or email worms
- Exploit known software vulnerabilities in order to spread
Notable Worms
- 1988: The Morris Worm, affects BSD unix machines. One of the first known buffer overruns
- 2000: The
ILOVEYOUworm, one of the most damaging worms ever, used social engineering to get people to install it.- Used the file name
LOVE-LETTER-FOR-YOU.txt.vbsas windows didn’t show the file type in the file name
- Used the file name
2003-2004
- During 2003 and 2004 worms were everywhere
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
- Spreading between machines on a internal network easily, no port filtering
- Used a buffer overflow in a windows Remote Procedure Call (RPC) service - spreads without the user clicking
- Compromised machines performed DDOS on
windowsupdate.com
- Netsky - Infected email attachment, actually removed other worms as part of a worm war
- Sasser - From the author of Netsky, attacks windows
LSASS- Spread 17 days after a patch to the vulnerability was released by Microsoft
- Buffer overflow in the Local Security and Authority Subsystem Service
LSASS - Scans IP addresses and infects via port 445
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
Exploit Life Cycle
- Many exploits are reverse engineered from patches, or developed simultaneously to patches
Zero-day Exploits
- An exploit that is previously unknown - by far the most dangerous
Stuxnet
- Believed to be an American-Israeli cyber weapon
- Uses four zero-day flaws to infect Windows
- Seeks out any instance of
Siemens Step7 - Finds programmable logic controllers (PLC)
- Detects attached centrifuges and spins them to destruction
- Reports that the centrifuges are fine
Trojans
- A malicious program pretending to be a legitimate application
- Often obtained in email attachments or at malicious websites
- Don’t replicated themselves - user error
- Randomware is the most common form of Trojan now
Notable Trojans
- 1989: The AIDS Trojan, encrypts all files filenames on the system and request random
- 2002: Beast, affects windows machines from 95-XP and provides the attack with a remote admin tool (RAT) - there are a lot of these types
- 2013: Cryptolocker - massive randomware
Ransomware
- Will usually encrypt or block access to files and demand ransom
- It is a clever solution, because if an anti-virus removes it, it is often too late
- Usually distributed on malicious websites, or to already infected machines
- The file decryption keys are protected by encrpyting using the public key of a C&C server
Ransomware Variants
- Most the challenge in successfully using randomware is tricking a user into running it, and bypassing anti-virus and browser protection
- Fake emails
- Malicious web pages
- Obfuscated javascript attachments
- Deployed using exploit kits
CryptoWall JS Example
- Everything is obfuscated
Crypto-jacking
- Coinhive is a Monero mining API released in September 2017
- It is a legitimate company, with an aim of replacing advertising on websites with currency mining
- This was exploited almost immediately
- Extremely easy to use the API
- Monero mining is pretty easy even on a CPU
- JavaScript is easy to inject onto websites via adverts





