Malware Introduction Flashcards
1
Q
What are the 3 malware types?
A
- Virus
- Trojan
- Worm
2
Q
What is a virus?
A
- Malicious executable
- Does not auto-replicate (interactions needed)
- Attaches to a ‘host’
- Inserts marker/flag to prevent reinfection
- .exe, shell scripts, batch files, macros.
3
Q
What is a metamorphic virus?
A
A virus that has a mutation engine that includes garbage code, compressing, instruction swapping, equivalent instruction inserter, that allows the virus to rewrite itself so it looks different each time it replicates.
4
Q
What is a polymorphic virus?
A
A virus that encrypts itself with a different key each time it replicates itself.
5
Q
What are worms?
A
- Malicious code that doesn’t need user interaction to spread
- Don’t need a host to attach to
- Auto-replicate/propagate via networks
- May carry a payload or attack tools
6
Q
How do worms spread?
A
- Windows Administrative Share
- Remote Shell Scripts
- Bugs in networking software (Stuxnet)
- Email spread
7
Q
What are trojans?
A
- Malware hidden inside innocuous programs - may use rootkits to hide
- Doesn’t self replicate
- Includes backdoors for CnC
- May include keyloggers, webcam control, etc.