Chap 5.3 Notes - Malware

Malware Threats: A Deep Dive

A Comprehensive Overview of Malicious Code and Cyber Attacks

What is Malware? Introduction to Malicious Code
  • Malware (Malicious Code): A broad term for any software intentionally designed to cause damage to a computer, server, client, or computer network.

  • Types of Malware Include:

    • Viruses & Worms

    • Ransomware

    • Rootkits

    • Trojan Horses

    • Backdoors & Covert Channel Tools

    • Spyware

    • Advanced Persistent Threats (APTs)

  • Potential Damage: Ranges from minor annoyances like displaying messages to catastrophic events like data destruction, file encryption for ransom, or complete system compromise.

Viruses vs. Worms Key Distinctions
  • Viruses:

    • Require a host program or file to infect.

    • Need human interaction to spread (e.g., opening an infected file, booting from an infected disk).

    • Analogy: Think of it like a biological virus needing a host cell to replicate.

  • Worms:

    • Are standalone software and do not require a host.

    • Can travel from system to system without human interaction.

    • Self-replicate to infect other systems.

    • Example: A worm can email itself to everyone in your address book, causing a massive amount of network traffic and potentially a Denial of Service (DoS) attack.

Virus Infection Methods (Part 1) How Viruses Spread and Attack
  • File Infection:

    • Relies on a user executing an infected file (commonly .com or .exe).

    • Often uses social engineering to trick users, like disguising an executable as an image file (.jpg, .png).

  • Fileless Infection:

    • A modern and stealthy technique (prominent since ~2017).

    • Exists exclusively in computer memory (RAM), leaving no files on the hard drive.

    • Trades persistence for stealth, making it harder for security software to detect.

  • Master Boot Record (MBR) Infection:

    • The original method of attack.

    • Infects the master boot record of a hard drive, executing when the computer boots up.

Virus Infection Methods (Part 2) More Ways Viruses Attack
  • BIOS Infection:

    • Targets the system’s Basic Input/Output System.

    • Can render a system completely inoperable, preventing it from even passing the Power-On Self-Test (POST).

  • Macro Infection:

    • Popular in the 1990s.

    • Exploits macro scripting services in applications like Microsoft Word, Excel, and PowerPoint.

  • Cluster Infection:

    • Modifies directory table entries.

    • When a user or process tries to access a legitimate program, it is redirected to the malware instead.

  • Multipartite Virus:

    • Uses multiple propagation methods.

    • Example: NATAS (Satan spelled backward) - targets both the boot sector and program files.

Virus Behavior and Evolution Stealth and Sophistication
  • Infection Rate:

    • Fast Infection: Spreads rapidly, infecting any file it can.

    • Sparse Infection: Infects files slowly and sporadically to avoid detection by antivirus software.

  • Advanced Malware:

    • Example: Flame (2012): Considered highly sophisticated. It could spread over a LAN, record audio, take screenshots, log keystrokes, and even turn infected computers into Bluetooth beacons to steal contact info from nearby devices.

  • Evasion Techniques:

    • Polymorphism: The virus changes its own code (signature) every time it replicates. This makes it much harder for signature-based antivirus programs to detect.

    • Targeted Attacks: Modern malware is often written for a specific target, limiting its spread. This makes it difficult for antivirus companies to obtain a sample and create a signature.

Virus Payloads: Where the Code Hides Infection Techniques
  • To avoid immediate detection and destruction of the host file, viruses often attach their code cleverly.

  • Prepender Virus:

    • Places its malicious code at the beginning of the infected file.

  • Appender Virus:

    • Places its malicious code at the end of the infected file.

  • Both methods leave the original file intact, simply adding the malicious code to it.

The Anatomy of a Virus Required and Optional Components
  • Required Components:

    • Search Routine: Finds new files, disk space, or RAM to infect. May include “profiling” to adapt the malware to the environment.

    • Infection Routine: Copies the virus and attaches it to a suitable host.

  • Optional Components:

    • Payload: The part of the malware that performs the malicious action (e.g., erasing a hard drive, displaying a message).

    • Anti-detection Routine: Helps the virus avoid being discovered by security software.

    • Trigger Routine: Launches the payload at a specific date, time, or when a certain condition is met.

The Anatomy of a Virus

Required Virus Components

  • Search Routine

  • Infection Routine

  • Anti-detection Routine

  • Trigger Routine

  • Payload

Trojan Horses: Deception and Destruction What is a Trojan?
  • Trojan: A program that disguises itself as something harmless or desirable but contains a malicious payload.

  • How they work:

    • A user is tricked into running a file they believe is safe (e.g., a PDF, a spreadsheet, a game).

    • When executed, the file delivers its malicious payload.

  • Characteristics:

    • Unlike viruses and worms, Trojans cannot spread by themselves. They rely entirely on tricking the user into executing them.

  • Payload Actions:

    • Granting remote access to the system.

    • Installing a keystroke logger.

    • Planting a backdoor.

    • Launching a Denial of Service (DoS) attack.

    • Disabling antivirus protection.

Types of Trojans (Part 1) A Rogues’ Gallery
  • Remote Access Trojans (RATs):

    • Give an attacker complete remote control over the victim’s system.

    • Examples: Poison Ivy, DarkComet.

  • Data Hiding / Ransomware:

    • Conceals or encrypts a user’s data, demanding a ransom for its release.

  • E-banking Trojans:

    • Specifically designed to steal banking information for financial gain.

    • They can intercept transaction numbers, inject fake forms into banking websites, and grab login credentials.

    • Examples: Zeus, Emotet.

  • Denial of Service (DoS) Trojans:

    • Designed to knock a specific service or an entire system offline by flooding it with traffic.

Types of Trojans (Part 2) More Malicious Varieties
  • Proxy Trojans:

    • Turn the victim’s computer into a proxy server.

    • Allows the attacker to hide their identity and perform malicious activities from the victim’s IP address.

  • FTP Trojans:

    • Open port 21 (FTP) to allow the attacker to upload, download, or transfer files on the victim’s machine.

  • Security-software Disablers:

    • Designed specifically to attack and disable antivirus programs and software firewalls, making the system more vulnerable to further attacks.

Trojan Goals What are the Attackers After?
  • Financial Data: Credit card numbers and banking information for online shopping sprees or to purchase services.

  • Digital Wallets: Stealing cryptocurrency (Bitcoin, Ethereum, etc.) or access to other electronic transaction services.

  • Passwords: Email passwords, online account passwords, etc. Password reuse makes this particularly dangerous.

  • Insider Information: Gaining access to critical information before it is made public.

  • Data Storage: Using the victim’s system as a storage space for illegal content like pirated software (warez), movies, or pornography.

  • Advanced Persistent Threat (APTs): As part of a larger, nation-state-sponsored attack targeting a company for its sensitive data.

    • Examples: Stuxnet, the 2011 attack against RSA.

Trojan Infection Mechanisms How Trojans Get In
  • Peer-to-Peer (P2P) Networks: Disguised as legitimate software like games or office suites on file-sharing sites.

  • Instant Messaging (IM) & Internet Relay Chat (IRC): Sending malicious files directly to users.

  • Email Attachments: The #1 means of malware propagation. Often disguised as important documents from legitimate organizations.

  • Physical Access: Copying the Trojan directly onto a system using a thumb drive.

  • SMS Messages: Propagating malware to mobile devices.

  • Browser Vulnerabilities: Exploiting bugs in un-updated web browsers.

  • Impersonated Mobile Apps: Malicious apps disguised as popular, legitimate apps in mobile stores.

  • Watering Hole Attack: Infecting a website that the attacker knows the victim will visit.

  • Freeware: Bundling Trojans with free software downloaded from untrusted sources.

Hiding Malware: The Art of Evasion Techniques for Distributing Trojans Undetected
  • Attackers use multiple layers of techniques to hide malware from antivirus engines and security researchers.

  • Wrappers (Binders):

    • Combine two or more executables (e.g., a legitimate program and a Trojan) into a single package.

    • Adds layers of obfuscation and encryption.

    • Example: BurnEye uses three layers: Obfuscation, Password, and Fingerprinting (to ensure the malware only runs in a specific environment).

Hiding Malware: The Art of Evasion
  • Figure 5-12: How Wrappers Work

    • Diagram illustrating how wrappers combine legitimate and malicious programs into a single package.

Hiding Malware: Packers, Droppers, and Crypters Advanced Evasion Tactics
  • Packers:

    • Compress malware files, similar to WinZip, but for the purpose of obfuscation.

    • The malware’s code is only decompressed when it is in memory and about to be executed, bypassing many detection systems.

  • Droppers:

    • Software designed solely to install a malware payload on a victim’s system.

    • Uses various methods to evade security controls during the installation process.

  • Crypters:

    • Encrypt or obscure the malware’s code to make it undetectable by signature-based antivirus.

    • Can use strong encryption (AES, RSA) or simple obfuscation (XOR, Base64).

    • Examples: Morphine, Yoda’s Crypter, Trojan Man.

The 4 Steps to Deploy a Trojan A Hacker’s Playbook
  1. Create or Obtain: The attacker first creates a Trojan or gets one from an existing toolkit.

  2. Modify: The Trojan is modified so that it is not detected by current antivirus software. This is where crypters and packers are used.

  3. Bind: The modified Trojan is bound (wrapped) with a legitimate file (e.g., an .exe, .pdf, .xls) to trick the user.

  4. Transmit: The final wrapped package is sent to the victim for execution via email, P2P, or other infection vectors.

Ransomware: The Digital Hostage Crisis Holding Your Data for Ransom
  • What it is: A type of malware that encrypts a victim’s personal files, making them inaccessible.

  • The Goal: The attacker demands a ransom payment (usually in cryptocurrency like Bitcoin) in exchange for the decryption key.

  • Propagation: Can spread like a worm or a virus.

  • Impact: Can encrypt specific files or, in some cases, the entire hard drive, including the master boot record.

  • Famous Examples:

    • WannaCry

    • Petya / NotPetya

    • CryptoLocker

    • Ryuk

Example: The WannaCry Ransomware Screen What a Victim Sees
  • The screen typically shows a threatening message explaining that files have been encrypted.

  • It includes a countdown timer, creating a sense of urgency. The ransom amount may increase after the timer expires, or the files may be permanently lost.

  • It provides instructions on how to pay the ransom, usually by sending Bitcoin to a specific digital wallet address.

Example: The WannaCry Ransomware Screen
  • Payment will be raised on 5/16/2017 00:47:55

  • Time Left: 02:23:57:37

  • Your files will be lost on 5/20/2017 00:47:55

  • About bitcoin

  • How to buy bitcoins?

  • Notification:

    • “Ooops, your files have been encrypted! English”

    • -