141 lines
5.1 KiB
Markdown
141 lines
5.1 KiB
Markdown
# Malware
|
||
|
||
**Malware** - **Mal**icious Soft**ware**
|
||
|
||
- A very general term, malware is usually categorised based on
|
||
- How it proliferates
|
||
- What it does
|
||
|
||

|
||
|
||
**Rootkit** - backdoor that installs itself in the kernel which makes it undetectable
|
||
|
||
### Vectors
|
||
|
||
- Vectors are the mechanism through which malware infects a machine
|
||
- Usually the vector will be a *software vulnerability*
|
||
- Or someone clicked something they shouldn’t have
|
||
|
||
### Payload
|
||
|
||
- Payloads are the actual malware deposited on the machine, or the harmful results
|
||
- They range in severity
|
||
- Essentially do nothing
|
||
- Messages and adverts
|
||
- Recruited into botnets or mail spam
|
||
- Stealing private information
|
||
- System destruction
|
||
- Ransomware & Crypto-jacking
|
||
|
||
#### Virus
|
||
|
||
- A piece of self-replicating code
|
||
- Propagates by attaching itself to a disk, file or document
|
||
- When the file is run, the virus runs and attempts to proliferate
|
||
- Installs without the users knowledge or consent
|
||
|
||
##### Notable Viruses
|
||
|
||
- 1981: `Elk Cloner`, the first known virus found *in the wild* that affected Apple II computers
|
||
- 1986: `Brain`, the first MS-DOS computer virus
|
||
- 1989: `Ghostball`, the first multipartite virus - affects both `exe`s and the boot sector
|
||
- 1995: First macro virus, `Concept`, affects MS Word documents
|
||
- 1996: First linux virus, `Staog`, uses bugs in the linux kernel
|
||
|
||
#### Worms
|
||
|
||
- Viruses traditionally require a human to spread
|
||
- Worms are self-replicating and stand-alone programs
|
||
- Do not require human intervention
|
||
- Scanning worms or email worms
|
||
- Exploit known software vulnerabilities in order to spread
|
||
|
||
##### Notable Worms
|
||
|
||
- 1988: The Morris Worm, affects BSD unix machines. One of the first known buffer overruns
|
||
- 2000: The `ILOVEYOU` worm, one of the most damaging worms ever, used social engineering to get people to install it.
|
||
- Used the file name `LOVE-LETTER-FOR-YOU.txt.vbs` as windows didn’t show the file type in the file name
|
||
|
||

|
||
|
||
### 2003-2004
|
||
|
||
- During 2003 and 2004 worms were everywhere
|
||
- SQL Slammer - fastest spreading worm, crashed the internet (only 376 bytes or 1 UDP packet)
|
||
- Even when the network was crippled, the occasional UDP packet could be transmitted and further damage the network
|
||
- MS Blaster - Windows XP mainly, crashes RPC and reboots your machine
|
||
- Spreading between machines on a internal network easily, no port filtering
|
||
- Used a buffer overflow in a windows Remote Procedure Call (RPC) service - spreads without the user clicking
|
||
- Compromised machines performed DDOS on `windowsupdate.com`
|
||
- Netsky - Infected email attachment, actually removed other worms as part of a *worm war*
|
||
- Sasser - From the author of Netsky, attacks windows `LSASS`
|
||
- Spread 17 days after a patch to the vulnerability was released by Microsoft
|
||
- Buffer overflow in the Local Security and Authority Subsystem Service `LSASS`
|
||
- Scans IP addresses and infects via port 445
|
||
|
||
#### Exploit Life Cycle
|
||
|
||
- Many exploits are reverse engineered from patches, or developed simultaneously to patches
|
||
|
||

|
||
|
||
##### Zero-day Exploits
|
||
|
||
- An exploit that is previously unknown - by far the most dangerous
|
||
|
||

|
||
|
||
###### Stuxnet
|
||
|
||
- Believed to be an American-Israeli cyber weapon
|
||
1. Uses *four zero-day flaws* to infect Windows
|
||
2. Seeks out any instance of `Siemens Step7`
|
||
3. Finds programmable logic controllers (PLC)
|
||
4. Detects attached centrifuges and spins them to destruction
|
||
5. Reports that the centrifuges are fine
|
||
|
||
### Trojans
|
||
|
||
- A malicious program pretending to be a legitimate application
|
||
- Often obtained in email attachments or at malicious websites
|
||
- Don’t replicated themselves - *user error*
|
||
- Randomware is the most common form of Trojan now
|
||
|
||
#### Notable Trojans
|
||
|
||
- 1989: The AIDS Trojan, encrypts all files filenames on the system and request random
|
||
- 2002: Beast, affects windows machines from 95-XP and provides the attack with a remote admin tool (RAT) - there are a lot of these types
|
||
- 2013: Cryptolocker - massive randomware
|
||
|
||
##### Ransomware
|
||
|
||
- Will usually encrypt or block access to files and demand ransom
|
||
- It is a clever solution, because if an anti-virus removes it, it is often too late
|
||
- Usually distributed on malicious websites, or to already infected machines
|
||
- The file decryption keys are protected by encrpyting using the *public key of a C&C server*
|
||
|
||
###### Ransomware Variants
|
||
|
||
- Most the challenge in successfully using randomware is tricking a user into running it, and bypassing anti-virus and browser protection
|
||
- Fake emails
|
||
- Malicious web pages
|
||
- Obfuscated javascript attachments
|
||
- Deployed using *exploit kits*
|
||
|
||
##### CryptoWall JS Example
|
||
|
||

|
||
|
||
- Everything is obfuscated
|
||
|
||
#### Crypto-jacking
|
||
|
||
- Coinhive is a Monero mining API released in September 2017
|
||
- It is a legitimate company, with an aim of replacing advertising on websites with currency mining
|
||
|
||

|
||
|
||
- This was exploited almost immediately
|
||
- Extremely easy to use the API
|
||
- Monero mining is pretty easy even on a CPU
|
||
- JavaScript is easy to inject onto websites via adverts |