Chap 5.3 Notes - Malware
Malware Threats: A Deep Dive
A Comprehensive Overview of Malicious Code and Cyber Attacks
What is Malware? Introduction to Malicious Code
Malware (Malicious Code): A broad term for any software intentionally designed to cause damage to a computer, server, client, or computer network.
Types of Malware Include:
Viruses & Worms
Ransomware
Rootkits
Trojan Horses
Backdoors & Covert Channel Tools
Spyware
Advanced Persistent Threats (APTs)
Potential Damage: Ranges from minor annoyances like displaying messages to catastrophic events like data destruction, file encryption for ransom, or complete system compromise.
Viruses vs. Worms Key Distinctions
Viruses:
Require a host program or file to infect.
Need human interaction to spread (e.g., opening an infected file, booting from an infected disk).
Analogy: Think of it like a biological virus needing a host cell to replicate.
Worms:
Are standalone software and do not require a host.
Can travel from system to system without human interaction.
Self-replicate to infect other systems.
Example: A worm can email itself to everyone in your address book, causing a massive amount of network traffic and potentially a Denial of Service (DoS) attack.
Virus Infection Methods (Part 1) How Viruses Spread and Attack
File Infection:
Relies on a user executing an infected file (commonly .com or .exe).
Often uses social engineering to trick users, like disguising an executable as an image file (.jpg, .png).
Fileless Infection:
A modern and stealthy technique (prominent since ~2017).
Exists exclusively in computer memory (RAM), leaving no files on the hard drive.
Trades persistence for stealth, making it harder for security software to detect.
Master Boot Record (MBR) Infection:
The original method of attack.
Infects the master boot record of a hard drive, executing when the computer boots up.
Virus Infection Methods (Part 2) More Ways Viruses Attack
BIOS Infection:
Targets the system’s Basic Input/Output System.
Can render a system completely inoperable, preventing it from even passing the Power-On Self-Test (POST).
Macro Infection:
Popular in the 1990s.
Exploits macro scripting services in applications like Microsoft Word, Excel, and PowerPoint.
Cluster Infection:
Modifies directory table entries.
When a user or process tries to access a legitimate program, it is redirected to the malware instead.
Multipartite Virus:
Uses multiple propagation methods.
Example: NATAS (Satan spelled backward) - targets both the boot sector and program files.
Virus Behavior and Evolution Stealth and Sophistication
Infection Rate:
Fast Infection: Spreads rapidly, infecting any file it can.
Sparse Infection: Infects files slowly and sporadically to avoid detection by antivirus software.
Advanced Malware:
Example: Flame (2012): Considered highly sophisticated. It could spread over a LAN, record audio, take screenshots, log keystrokes, and even turn infected computers into Bluetooth beacons to steal contact info from nearby devices.
Evasion Techniques:
Polymorphism: The virus changes its own code (signature) every time it replicates. This makes it much harder for signature-based antivirus programs to detect.
Targeted Attacks: Modern malware is often written for a specific target, limiting its spread. This makes it difficult for antivirus companies to obtain a sample and create a signature.
Virus Payloads: Where the Code Hides Infection Techniques
To avoid immediate detection and destruction of the host file, viruses often attach their code cleverly.
Prepender Virus:
Places its malicious code at the beginning of the infected file.
Appender Virus:
Places its malicious code at the end of the infected file.
Both methods leave the original file intact, simply adding the malicious code to it.
The Anatomy of a Virus Required and Optional Components
Required Components:
Search Routine: Finds new files, disk space, or RAM to infect. May include “profiling” to adapt the malware to the environment.
Infection Routine: Copies the virus and attaches it to a suitable host.
Optional Components:
Payload: The part of the malware that performs the malicious action (e.g., erasing a hard drive, displaying a message).
Anti-detection Routine: Helps the virus avoid being discovered by security software.
Trigger Routine: Launches the payload at a specific date, time, or when a certain condition is met.
The Anatomy of a Virus
Required Virus Components
Search Routine
Infection Routine
Anti-detection Routine
Trigger Routine
Payload
Trojan Horses: Deception and Destruction What is a Trojan?
Trojan: A program that disguises itself as something harmless or desirable but contains a malicious payload.
How they work:
A user is tricked into running a file they believe is safe (e.g., a PDF, a spreadsheet, a game).
When executed, the file delivers its malicious payload.
Characteristics:
Unlike viruses and worms, Trojans cannot spread by themselves. They rely entirely on tricking the user into executing them.
Payload Actions:
Granting remote access to the system.
Installing a keystroke logger.
Planting a backdoor.
Launching a Denial of Service (DoS) attack.
Disabling antivirus protection.
Types of Trojans (Part 1) A Rogues’ Gallery
Remote Access Trojans (RATs):
Give an attacker complete remote control over the victim’s system.
Examples: Poison Ivy, DarkComet.
Data Hiding / Ransomware:
Conceals or encrypts a user’s data, demanding a ransom for its release.
E-banking Trojans:
Specifically designed to steal banking information for financial gain.
They can intercept transaction numbers, inject fake forms into banking websites, and grab login credentials.
Examples: Zeus, Emotet.
Denial of Service (DoS) Trojans:
Designed to knock a specific service or an entire system offline by flooding it with traffic.
Types of Trojans (Part 2) More Malicious Varieties
Proxy Trojans:
Turn the victim’s computer into a proxy server.
Allows the attacker to hide their identity and perform malicious activities from the victim’s IP address.
FTP Trojans:
Open port 21 (FTP) to allow the attacker to upload, download, or transfer files on the victim’s machine.
Security-software Disablers:
Designed specifically to attack and disable antivirus programs and software firewalls, making the system more vulnerable to further attacks.
Trojan Goals What are the Attackers After?
Financial Data: Credit card numbers and banking information for online shopping sprees or to purchase services.
Digital Wallets: Stealing cryptocurrency (Bitcoin, Ethereum, etc.) or access to other electronic transaction services.
Passwords: Email passwords, online account passwords, etc. Password reuse makes this particularly dangerous.
Insider Information: Gaining access to critical information before it is made public.
Data Storage: Using the victim’s system as a storage space for illegal content like pirated software (warez), movies, or pornography.
Advanced Persistent Threat (APTs): As part of a larger, nation-state-sponsored attack targeting a company for its sensitive data.
Examples: Stuxnet, the 2011 attack against RSA.
Trojan Infection Mechanisms How Trojans Get In
Peer-to-Peer (P2P) Networks: Disguised as legitimate software like games or office suites on file-sharing sites.
Instant Messaging (IM) & Internet Relay Chat (IRC): Sending malicious files directly to users.
Email Attachments: The #1 means of malware propagation. Often disguised as important documents from legitimate organizations.
Physical Access: Copying the Trojan directly onto a system using a thumb drive.
SMS Messages: Propagating malware to mobile devices.
Browser Vulnerabilities: Exploiting bugs in un-updated web browsers.
Impersonated Mobile Apps: Malicious apps disguised as popular, legitimate apps in mobile stores.
Watering Hole Attack: Infecting a website that the attacker knows the victim will visit.
Freeware: Bundling Trojans with free software downloaded from untrusted sources.
Hiding Malware: The Art of Evasion Techniques for Distributing Trojans Undetected
Attackers use multiple layers of techniques to hide malware from antivirus engines and security researchers.
Wrappers (Binders):
Combine two or more executables (e.g., a legitimate program and a Trojan) into a single package.
Adds layers of obfuscation and encryption.
Example: BurnEye uses three layers: Obfuscation, Password, and Fingerprinting (to ensure the malware only runs in a specific environment).
Hiding Malware: The Art of Evasion
Figure 5-12: How Wrappers Work
Diagram illustrating how wrappers combine legitimate and malicious programs into a single package.
Hiding Malware: Packers, Droppers, and Crypters Advanced Evasion Tactics
Packers:
Compress malware files, similar to WinZip, but for the purpose of obfuscation.
The malware’s code is only decompressed when it is in memory and about to be executed, bypassing many detection systems.
Droppers:
Software designed solely to install a malware payload on a victim’s system.
Uses various methods to evade security controls during the installation process.
Crypters:
Encrypt or obscure the malware’s code to make it undetectable by signature-based antivirus.
Can use strong encryption (AES, RSA) or simple obfuscation (XOR, Base64).
Examples: Morphine, Yoda’s Crypter, Trojan Man.
The 4 Steps to Deploy a Trojan A Hacker’s Playbook
Create or Obtain: The attacker first creates a Trojan or gets one from an existing toolkit.
Modify: The Trojan is modified so that it is not detected by current antivirus software. This is where crypters and packers are used.
Bind: The modified Trojan is bound (wrapped) with a legitimate file (e.g., an .exe, .pdf, .xls) to trick the user.
Transmit: The final wrapped package is sent to the victim for execution via email, P2P, or other infection vectors.
Ransomware: The Digital Hostage Crisis Holding Your Data for Ransom
What it is: A type of malware that encrypts a victim’s personal files, making them inaccessible.
The Goal: The attacker demands a ransom payment (usually in cryptocurrency like Bitcoin) in exchange for the decryption key.
Propagation: Can spread like a worm or a virus.
Impact: Can encrypt specific files or, in some cases, the entire hard drive, including the master boot record.
Famous Examples:
WannaCry
Petya / NotPetya
CryptoLocker
Ryuk
Example: The WannaCry Ransomware Screen What a Victim Sees
The screen typically shows a threatening message explaining that files have been encrypted.
It includes a countdown timer, creating a sense of urgency. The ransom amount may increase after the timer expires, or the files may be permanently lost.
It provides instructions on how to pay the ransom, usually by sending Bitcoin to a specific digital wallet address.
Example: The WannaCry Ransomware Screen
Payment will be raised on 5/16/2017 00:47:55
Time Left: 02:23:57:37
Your files will be lost on 5/20/2017 00:47:55
About bitcoin
How to buy bitcoins?
Notification:
“Ooops, your files have been encrypted! English”
-