More Malware Last Class Worms: Morris Worm Stuxnet Conficker - - PowerPoint PPT Presentation
More Malware Last Class Worms: Morris Worm Stuxnet Conficker - - PowerPoint PPT Presentation
More Malware Last Class Worms: Morris Worm Stuxnet Conficker Web-based malware: Exploit kits Fake AV Ransomware Today (continuation) How Malware Spreads Adware Computer Virus A type of malicious
Last Class
- Worms:
- Morris Worm
- Stuxnet
- Conficker
- Web-based malware:
- Exploit kits
- Fake AV
- Ransomware
Today
- (continuation) How Malware Spreads
- Adware
Computer Virus
- A type of malicious software program ("malware")
that, when executed, replicates itself by modifying
- ther computer programs and inserting its own
- code. - Wikipedia
Parts of a Virus
- Infection vector: How a virus spreads
- Trigger: Sets off the malicious functionality
- Payload: The malicious functionality
Phases of a Virus
Dormant Scanning and Propagating Waiting for a trigger Execute
triggered
How do they infect?
Malware Executable File
How do they infect?
Malware Executable File
How do they infect?
Executable File Malware
How do they infect?
Executable File Malware
How do they infect?
Executable File Malware Malware
How do they infect?
Malware
How do they infect?
Executable File Malware
Packer
How do they execute?
Executable File Malware Line of code
How do they execute?
Executable File Malware Line of code
Definitions
- Self-Modifying code: Code that can change itself
(usually without changing the functionality)
- Polymorphic malware: Infects others with an encrypted
copy of itself. Encryption and code changes.
- Backdoor: Malware that leaves hidden ways of
replicating itself
- Rootkit: Malicious software to maintain access to
system; good at hiding itself.
ILOVEYOU
- Bug in email: sent out messages
subject:ILOVEYOU and attachment:LOVE-LETTER- FOR-YOU.txt.vbs
- .vbs files were hidden
- Propogation: Sent itself to all addresses in address
book
- Payload: Overwrote random files
Adware
- Software that contains unwanted ads
Types of Ad Fraud
- Pretend to be part of the ad chain and buy traffic,
get paid.
- Have bots, sell fake ad traffic
- Disguise source of traffic to ads
- Cookie stuffing — fake affiliate cookies
- Ad Stacking — show invisible ads to consumer
Adblock Plus
- Browser-based Ad blocker
- Let in some “acceptible” ads
- Is this adware? Fraud?
Fake Software
- Stuffing ads into software
- Maybe turning paid software into freeware?
- Is this adware? fraud?
DNSChanger
- Upon infecting your computer, changed your
routers’ nameserver settings.
- Started in 2006. FBI raided in 2011. Shut down in
- 2012. Still alive today.
- Main changes? Major ad networks
- Is this adware? fraud?
My Really Cool Toolbar
- Lots of toolbars, other browser extensions
- Useful functionality
- Changed settings (homepage, etc)
- Hard to Remove
- Is this adware? fraud?