techPowerUp! Forums

Go Back   techPowerUp! Forums > Hardware > Networking & Security

Reply
 
Thread Tools
Old Oct 30, 2012, 10:27 AM   #1
95Viper
3500 Posts
 
95Viper's Avatar
 
Join Date: Oct 2008
Location: στο άλφα έως ωμέγα
Posts: 3,842 (2.28/day)
Thanks: 2,034
Thanked 1,418 Times in 1,117 Posts

System Specs

Smarter malware... Less technical coding

How about malware that will peek at what might be monitoring for it, then hide or wait a few minutes run a portion of itself.
Wait, now run another portion. Oh, wait, and run some more.
Bam your infected!

Or, how about some malware that hides in your mouse routines, then waits for you to click a button or move the mouse, so it can run hidden in the mouse message routines.

Even better, how 'bout the malware that will recognize it is running in a VM or being searched for and stops itself from running; hide and waits until the the way is clear.

And, unless your A/V or whatever method you use is aware of this type of threat... you are infected.

Now a days, it doesn't take a technical genius to make it happen.

It is all explained in this article by the Symantec Security Response team, here -->Malware Authors Using New Techniques to Evade Automated Threat Analysis Systems
And, a couple of quotes from the page:
Quote:
For a long time, malware has been able to detect the environment it is running in and hide itself from automated threat analysis systems. The list below is the measures malware takes avoid being detected by dynamic analyzer systems:
Checks a certain registry entry and stops if it detects that it is running in a virtual environment.
Checks video and mouse drivers and stops if it detects that it is running in a virtual environment.
Enumerates the system service list and stops if it detects that it is running in a virtual environment.
Executes special assembler code and stops if it detects that it is running in a virtual environment.
Checks a certain communication port and stops if it detects that it is running in a virtual environment.
Checks a certain process name and stops if it detects that it is being monitored.

If malware stops itself when it detects that it is running in a virtual environment, it may trick an automated threat analysis system into thinking that it is a clean program. It is also able to stop itself if it discovers a certain process name and detects that someone is monitoring it. So malware may not only fool automated threat analysis systems, but also a corporate system administrator who is searching for computers compromised by malware
Quote:
In the past, malware authors used very difficult techniques to detect virtual environments. As such, they may have needed specialized skills, such as assembler code writing skills, knowledge of virtual machines, and knowledge of CPUs and memory management.

However, the techniques described in this blog are not technical and hence malware authors these days do not need technical skills to hide their creations from automated threat analysis systems. Furthermore, they are always researching and testing new ideas in order to fool automated threat analysis systems.
Keep your guard up and compute safely.

Last edited by 95Viper; Oct 30, 2012 at 10:36 AM.
95Viper is offline  
Reply With Quote
Old Nov 2, 2012, 09:43 AM   #2
SoF
25 Posts
 
SoF's Avatar
 
Join Date: Nov 2008
Location: c:\windows
Posts: 28 (0.02/day)
Thanks: 3
Thanked 29 Times in 11 Posts

Good article!

These damn little suckers are really clever these days...

Still I will never get over the point why people with such coding skills are not doing something good instead beeing a pest for everyone.
__________________
SoF is offline  
Reply With Quote
The Following User Says Thank You to SoF For This Useful Post:
Old Nov 2, 2012, 10:45 AM   #3
mediasorcerer
500 Posts
 
mediasorcerer's Avatar
 
Join Date: Sep 2011
Location: coast ,melbourne
Posts: 942 (1.52/day)
Thanks: 709
Thanked 235 Times in 169 Posts

System Specs

Theyre doing something good for the anti virus companies.
__________________
his masters voice

Illuminous Epanoia Technocrati
mediasorcerer is offline  
Reply With Quote
The Following User Says Thank You to mediasorcerer For This Useful Post:
Old Nov 2, 2012, 11:31 AM   #4
Aquinus
3500 Posts
 
Aquinus's Avatar
 
Join Date: Jan 2012
Location: Dover, New Hampshire, USA
Posts: 4,276 (8.85/day)
Thanks: 1,284
Thanked 1,333 Times in 989 Posts

System Specs

There is no bit of software that cannot be circumvented. It's a matter of taking the time to find out how to do it. Nothing is 100% fail-safe. This is true for everything. OS, DRM, Viruses/Malware, anything.
__________________
MyHeat
Aquinus is offline  
Crunching for Team TPU
Reply With Quote
Old Nov 2, 2012, 11:45 AM   #5
eidairaman1
Eligible for custom title
 
eidairaman1's Avatar
 
Join Date: Jul 2007
Location: HTX
Posts: 10,080 (4.68/day)
Thanks: 1,359
Thanked 1,159 Times in 1,035 Posts
Send a message via MSN to eidairaman1

System Specs

Quote:
Originally Posted by mediasorcerer View Post
Theyre doing something good for the anti virus companies.
considering most Virual code comes from them anyways.

Tools that help

Spyware Blaster
Spybot Search and Destroy
Malware Bytes Anti Malware
Hijack This
Housecall
AdAware
Webroot Spysweeper
__________________
Athlon XP USERS with COD 4 FIX
http://www.techsupportforum.com/foru...ls-202011.html
http://www.howorks.com/2011/02/24/ho...-memory-limit/
“Sometimes my level of fail is unprecedented.” -TheMailMan78
“This is what the force of a thousand suns looks like.” -3870x2
eidairaman1 is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Lenovo Adds Smarter Classmate+ Laptop & Convertible to Education Roster Cristian_25H News 0 Jan 12, 2012 06:42 AM
Want to be smarter? twilyth Science & Technology 3 Jun 25, 2011 08:50 PM
WD Unveils Smaller, Smarter and More Secure My Passport Essential Drives btarunr News 3 Sep 11, 2009 10:23 AM
Microsoft Makes WGA Smarter zekrahminator News 17 Feb 24, 2008 03:29 AM


All times are GMT. The time now is 07:21 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts