Posts

Showing posts with the label Malware

Worms: Self-Propagating Malware and Why Segmentation Stops It

A worm is malware that spreads on its own. No user has to open anything, click anything, or plug anything in. That single property — self-propagation without user action — is what separates a worm from a virus, and it is the distinction the exam tests most often. Worm, virus, trojan A virus attaches itself to a file or program and requires a user to run that host. Its spread is bounded by how often people share and execute files. A worm is a standalone program that finds new hosts and copies itself to them by exploiting a service or using stolen credentials. Its spread is bounded only by network reachability and how fast it can scan — which is to say, not much. A trojan is malware disguised as something desirable. It depends entirely on persuading the user, and it does not self-replicate. The categories overlap in real samples. Modern malware frequently arrives as a trojan through a phishing message and then behaves like a worm once inside, which is the combi...

Process Injection: How Code Ends Up Running Inside Something Legitimate

Process injection makes code run inside a process that already exists. The malicious code inherits that process's identity, its privileges, and its reputation — so network connections appear to come from a signed, trusted application, and a scanner looking for suspicious files finds nothing because the code was never a file on disk. Why attackers do it Three benefits, and they compound. Evasion. Application allowlisting permits the legitimate process, and it is the legitimate process that is running. File-based scanning has no file to examine. Behavioural analysis sees activity attributed to a trusted binary. Privilege and access. Injecting into a process running with higher privileges, or one already holding credentials and open handles, grants those without exploiting anything further. Plausibility. Outbound connections from a browser process look entirely normal. The same connections from an unknown executable in a temporary directory do not. The techniques, roughly ...

Reverse Engineering Basics: Static and Dynamic Malware Analysis

Reverse engineering a binary means working out what it does without source code. In security work the goal is almost never full comprehension — it is answering specific questions: what does this sample do, what does it talk to, what did it leave behind, and what indicators can I hunt for across the estate. Static analysis Static analysis examines the file without running it, which makes it safe and fast. Start with the cheap signals. The file hash checked against reputation services often identifies a known sample in seconds — though note that submitting a hash discloses that you have it, and uploading the file discloses the file, which matters for targeted samples and internal tooling. Extracting printable strings frequently yields URLs, domain names, file paths, registry keys, error messages, and command fragments. It is crude and it is the highest return per minute of any technique. The file header tells you the format, the target architecture, the compile timestamp...

Adware Explained: Removal, PUPs and Spyware Differences for the A+ Exam

Adware is software that displays advertising you did not ask for, usually by injecting ads into web pages, opening pop-ups, or redirecting searches. It sits in an awkward middle ground between legitimate software and outright malware, and that ambiguity is exactly what makes it worth understanding. Adware is the least dangerous malware category and the most common one. It is also the symptom that tells you something else got in. That last point is the one most often missed. Adware rarely arrives alone. Its presence means something was installed without proper consent or oversight, which means the same route is open to anything else. How It Gets In Bundling is by far the most common route. A free utility's installer offers a browser toolbar, a "PC optimizer", or a search extension, pre-ticked, on a screen most people click straight through. Technically the user consented. Practically they did not read it, which is why adware is often classed as a potentially unwa...

Malware Types Part 3: Rootkits, Fileless Malware and Persistence

Part 1 covered how malware arrives and Part 2 covered what it does. This article covers the two problems every attacker must solve after that: staying hidden, and surviving a reboot. Rootkits and the level they operate at A rootkit hides the presence of malware by interfering with what the system reports about itself. What it can hide depends entirely on how deep it runs, and the exam cares about that hierarchy. User-mode rootkits hook application-level functions, so a process or file is missing from a listing produced by normal tools. They are the easiest to write and the easiest to find, because anything querying the kernel directly sees past them. Kernel-mode rootkits load as a driver and manipulate the operating system's own data structures. At that point the system is lying to every tool running on it, including security software, because they are all asking the compromised kernel. Driver signing requirements and kernel integrity protections exist specifically to make...

Malware Types Part 2: Ransomware, Spyware and Other Payloads

Part 1 classified malware by how it arrives. This article classifies it by what it does once it is running — the payload — because that is what determines your impact, your response, and which control would have helped. Ransomware Ransomware encrypts data and demands payment for the key. It is the payload with the clearest business impact, and the model has evolved in ways worth knowing. Double extortion is now standard: data is stolen before it is encrypted, so paying for decryption does not remove the threat of publication. This broke the reasoning that good backups make ransomware survivable — backups restore availability and do nothing about disclosure, which is a breach requiring notification regardless of whether you paid. Modern operations are human-operated rather than automatic. Attackers gain access, spend days moving laterally and stealing credentials, identify and destroy backups, then deploy encryption everywhere at once. That dwell time is also the...

Malware Types Part 1: Viruses, Worms, Trojans and How They Spread

Malware is classified two different ways, and mixing them up is the fastest route to a wrong answer. One axis is how it gets there — propagation. The other is what it does once it arrives — payload. A single sample usually has one of each: a trojan that delivers ransomware, or a worm that installs a backdoor. This article covers propagation. Part 2 covers payloads, and Part 3 covers stealth and persistence. Viruses A virus attaches itself to a host file or program and spreads when a user executes that host. It cannot run on its own, and it cannot spread without human action — that dependency is its defining characteristic. Subtypes appear on exams. A boot sector virus infects the boot record and loads before the operating system. A macro virus lives in a document's scripting language, which is why macros from the internet are disabled by policy in any well-run environment. A polymorphic virus changes its own code each time it replicates to defeat signature mat...