PM - Section 1.1 Malware Flashcards
Name some malware types
Viruses Crypto-malware (used to encrypt all your data) Ransomware Worms trojan horse Rootkit Keylogger Adware/Spyware Botnet
What is malware?
Malicious software
How do you get malware?
Exploits a vulnerability and installs a remote access backdoor.
Your computer must execute a program - email link, popup, drive by download, worm.
What is a virus?
Can be propagate from device to device and replicate. Reproduces through file systems or network. Many are invisible.
What are some types of viruses?
Program viruses - part of application.
Boot sector viruses
Script viruses - OS based and browser based
Macro viruses - common in MS office.
What is a worm?
A worm is a type of virus that can move itself from one computer to another. No human interaction needed. Uses network as a transmission medium.
How to stop a worm?
Firewalls
IDS/IPS can mitigate worms effects.
Intrusion Prevention System.
What is the WannaCry worm?
Affects Windows systems. Looks for a vulnerable system installs EternalBlue. EB installs a backdoor and downloads WannaCry
What is ransomware?
Computer is locked and encrypted until you pay for a ransom. Can be fake and just be a splash screen.
What is crypto-malware?
Encrypts all data files, but OS still works until you pay for the decryption key. (A public key cryptography)
How to avoid a crypto-malware attack?
Have a backup of your files off line. Keep OS up-to-date.
What is a Trojan Horse?
Pretends to be something else. Doesn’t replicate.
What is a backdoor?
Opens up a channel to allow other malware to get in. Any software could have a backdoor!
What is a RAT?
Remote Access Trojans/ Remote Administration Tools
Downloaded with other software and allows allows admin control. E.g. Key logger, screen-recordings, copy files, install more malware.
What is a RootKit?
Unix/Linux devices. It modifies the kernel of the OS. Antivirus/anti-malware software cannot find it. It’s invisible to the OS.