Files
notes/docs/lectures/security/09_malware.md
T

141 lines
5.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Malware
**Malware** - **Mal**icious Soft**ware**
- A very general term, malware is usually categorised based on
- How it proliferates
- What it does
![1646673601.png](img/1646673601.png)
**Rootkit** - backdoor that installs itself in the kernel which makes it undetectable
### Vectors
- Vectors are the mechanism through which malware infects a machine
- Usually the vector will be a *software vulnerability*
- Or someone clicked something they shouldn’t have
### Payload
- Payloads are the actual malware deposited on the machine, or the harmful results
- They range in severity
- Essentially do nothing
- Messages and adverts
- Recruited into botnets or mail spam
- Stealing private information
- System destruction
- Ransomware & Crypto-jacking
#### Virus
- A piece of self-replicating code
- Propagates by attaching itself to a disk, file or document
- When the file is run, the virus runs and attempts to proliferate
- Installs without the users knowledge or consent
##### Notable Viruses
- 1981: `Elk Cloner`, the first known virus found *in the wild* that affected Apple II computers
- 1986: `Brain`, the first MS-DOS computer virus
- 1989: `Ghostball`, the first multipartite virus - affects both `exe`s and the boot sector
- 1995: First macro virus, `Concept`, affects MS Word documents
- 1996: First linux virus, `Staog`, uses bugs in the linux kernel
#### Worms
- Viruses traditionally require a human to spread
- Worms are self-replicating and stand-alone programs
- Do not require human intervention
- Scanning worms or email worms
- Exploit known software vulnerabilities in order to spread
##### Notable Worms
- 1988: The Morris Worm, affects BSD unix machines. One of the first known buffer overruns
- 2000: The `ILOVEYOU` worm, one of the most damaging worms ever, used social engineering to get people to install it.
- Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as windows didn’t show the file type in the file name
![1646674683.png](img/1646674683.png)
### 2003-2004
- During 2003 and 2004 worms were everywhere
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
- Spreading between machines on a internal network easily, no port filtering
- Used a buffer overflow in a windows Remote Procedure Call (RPC) service - spreads without the user clicking
- Compromised machines performed DDOS on `windowsupdate.com`
- Netsky - Infected email attachment, actually removed other worms as part of a *worm war*
- Sasser - From the author of Netsky, attacks windows `LSASS`
- Spread 17 days after a patch to the vulnerability was released by Microsoft
- Buffer overflow in the Local Security and Authority Subsystem Service `LSASS`
- Scans IP addresses and infects via port 445
#### Exploit Life Cycle
- Many exploits are reverse engineered from patches, or developed simultaneously to patches
![1646675422.png](img/1646675422.png)
##### Zero-day Exploits
- An exploit that is previously unknown - by far the most dangerous
![1646675515.png](img/1646675515.png)
###### Stuxnet
- Believed to be an American-Israeli cyber weapon
1. Uses *four zero-day flaws* to infect Windows
2. Seeks out any instance of `Siemens Step7`
3. Finds programmable logic controllers (PLC)
4. Detects attached centrifuges and spins them to destruction
5. Reports that the centrifuges are fine
### Trojans
- A malicious program pretending to be a legitimate application
- Often obtained in email attachments or at malicious websites
- Don’t replicated themselves - *user error*
- Randomware is the most common form of Trojan now
#### Notable Trojans
- 1989: The AIDS Trojan, encrypts all files filenames on the system and request random
- 2002: Beast, affects windows machines from 95-XP and provides the attack with a remote admin tool (RAT) - there are a lot of these types
- 2013: Cryptolocker - massive randomware
##### Ransomware
- Will usually encrypt or block access to files and demand ransom
- It is a clever solution, because if an anti-virus removes it, it is often too late
- Usually distributed on malicious websites, or to already infected machines
- The file decryption keys are protected by encrpyting using the *public key of a C&C server*
###### Ransomware Variants
- Most the challenge in successfully using randomware is tricking a user into running it, and bypassing anti-virus and browser protection
- Fake emails
- Malicious web pages
- Obfuscated javascript attachments
- Deployed using *exploit kits*
##### CryptoWall JS Example
![1646676226.png](img/1646676226.png)
- Everything is obfuscated
#### Crypto-jacking
- Coinhive is a Monero mining API released in September 2017
- It is a legitimate company, with an aim of replacing advertising on websites with currency mining
![1646676407.png](img/1646676407.png)
- This was exploited almost immediately
- Extremely easy to use the API
- Monero mining is pretty easy even on a CPU
- JavaScript is easy to inject onto websites via adverts