Top Banner
Learning MALWARE ! for fun and profit SRINU [email protected]
26
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Learning  malware for fun and profit

LearningMALWARE !for fun and

profitSRINU

[email protected]

Page 2: Learning  malware for fun and profit

OVERVIEW

What is malware?

Types of malwares.

How to create your own malware (Educational purpose only)

Writing signatures to antiviruses.

Evading antiviruses. (Educational purpose only)

Page 3: Learning  malware for fun and profit

What is a malware ? Malware short for malicious software . malware is a piece of software that is designed to disrupt operation , gather information , gain unauthorized access to system resources, and for exploitation purposes.

The malware is a general term used by a computer professionals to mean a variety of forms of hostile , intrusive, or annoying software or programming code.

In simply malware is a set of instructions that run on your computer and make your system do something that an attacker wants it to do.

Page 4: Learning  malware for fun and profit

Types of malwareThere are many types of malwares are there. most common are :

VirusesWormsRootkitsTrojansBackdoors SpywareKeyloggerAdwareCrimewareScareware

This list goes on …………………

Page 5: Learning  malware for fun and profit

What is a Virus?

A computer virus is a program that can replicate itself and spread from one computer to another.

if a computer program is called as a virus it most have the capability to spread from one file to another file and one computer to another computer by means of Network or internet or carried it by a removable devices like CD’s, DVD’s, Floppy disks and USB devices.

in simply virus is a program that can infect other programs by modifying them to include a, possibly evolved, version of itself.

Page 6: Learning  malware for fun and profit

Indications of Virus attack

Hard drive is accessed even when not using the computer.Computer freezes frequently or encounters errors.Computer slows down when programs starts.Files and Folders are missing (god has to know what happened to files).Unable to load operating system files.Browser window freezes.

Page 7: Learning  malware for fun and profit

When computer get infected by Viruses

Don’t having proper antivirus application.Not updating antivirus and operating system and applications.Installing pirated software's and rouge applications.Opening an infected E-Mail attachments.

Page 8: Learning  malware for fun and profit

How to create your own Virus (Educational purpose only)

DEMO

Page 9: Learning  malware for fun and profit

What is a Worm

A computer worm is a self-replicating malware which uses a computer network to send copies of itself to another computer.

However, a computer worm does not need to attach itself to a program in your system like a computer virus does in order to function. A computer worm generally localizes its damage to the computer network by causing increased bandwidth(only applicable to old worm types )

Page 10: Learning  malware for fun and profit

Indications of worm attacks

• Unusual network traffic in pc• Not able to visit websites due to bandwidth is

flooded by worm.• Unusual files in network shares.• Unable to update antiviruses.

Page 11: Learning  malware for fun and profit

How Worm spreads

Peer 2 peer (p2p) networks like uTorrent.

Infected USB devices.

Network shares. Emails

Page 12: Learning  malware for fun and profit
Page 13: Learning  malware for fun and profit

How to create your own Worm (Educational purpose only)

DEMO

Page 14: Learning  malware for fun and profit

Rootkit

Rootkit is a stealthy type of malware designed to hide its existence from processes viewer and other monitor software's.

Page 15: Learning  malware for fun and profit

Types of rootkits

• There are two different types of rootkits. they are :–User Mode rootkit–Kernel Mode rootkit

User Mode

Supervisor /Kernel Mode

Page 16: Learning  malware for fun and profit

Backdoors• A Backdoor is a way in to the system that

allows an attacker to access the victim machine.

• after penetrating the victim machine the attacker installs the backdoor in it.

• it used to access the victim machine.

• Example: NetCat

Page 17: Learning  malware for fun and profit

Backdoor !!!!

Hey got the backdoor. PWNED

Page 18: Learning  malware for fun and profit

Trojan

• Trojan is a piece of software which contains both legitimate code and malicious code.

• performs covert and overt actions.• Frequently embedded in applets, games and

email attachments.• Examples

– Beast– ProRat

Page 19: Learning  malware for fun and profit

Small story about Trojan

Page 20: Learning  malware for fun and profit

How to create your own Trojan (Educational purpose only)

DEMO

Page 21: Learning  malware for fun and profit

Best Tips to Defend Against Malware

Protect your computer with strong security software and

keep updated.

Enable automatic Windows updates.

Be careful when engaging in peer-to-peer (P2P) file-

sharing.

Beware of spam-based phishing

schemes.

Back up your files

regularly.

Page 22: Learning  malware for fun and profit

Writing signatures to antiviruses

Mostly antivirus signature writers use three methods to create signatures They are:

MD5 hashes Byte code Heuristic

Page 23: Learning  malware for fun and profit

AgainDEMO

Page 24: Learning  malware for fun and profit

Evading Antiviruses

AgainAn Awesome

DEMO

Page 25: Learning  malware for fun and profit

Any Queries

Page 26: Learning  malware for fun and profit

SpecialThanks

to

Raghu

chaitu

Imran