Section 6.47 Viruses Flashcards

Objectives 2.4 Given a Scenario, analyse indicators of malicious activity

1
Q

Viruses

A

Made up of malicious code that’s run on a machine without the user’s knowledge and this allows the code to infect the computer whenever it has been run

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

10 Different types of Viruses BAMSHPPEMM

1 Boot Sector

A

One that is stored in the first sector of a hard drive and is then loaded by the bootstrap loader into memory whenever the computer boots up

Hard to detect need specific anti virus that looks for boot sector during the boot up process of a computer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

10 Different types of Viruses BAMSHPPEMM

2 Macro

A

Form of code that allows a virus to be embedded inside another
document so that when that document is opened by the user, the virus is executed

Macros are used in software like excel and is normally fine. However this code can be manipulated by attackers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

10 Different types of Viruses BAMSHPPEMM

3 Program

A

Attackers try to find executables or application files to infect with their malicious code

Virus that tries to install itself on prgrammes and application like Word.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

10 Different types of Viruses BAMSHPPEMM

4 Multipartite

A

Combination of a boot sector type virus and a program virus. Able to place itself in the boot sector and be loaded every time the computer boots. It can install itself in a program where it can be run every time the computer starts up

Cyber Security analysts can easily miss the boot aspect of the virus and only clean up the program virus.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

10 Different types of Viruses BAMSHIPPEM

5 Encrypted

A

Designed to hide itself from being detected by encrypting its malicious code or payloads to avoid detection by any antivirus software

Malicious code is scrambled in to cyper text

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

10 Different types of Viruses BAMSHPPEMM

6 Polymorphic

A

Advanced version of an encrypted virus, but instead of just encrypting the contents it will actually change the viruses code each time it is executed by altering the decryption module in order for it to evade detection

Morph the way the code looks so that its signature based anti-virus applications are not going to detect it as being malicious

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

10 Different types of Viruses BAMSHPPEMM

7 Metamorphic

A

Able to rewrite themselves entirely before it attempts to infect a given file

More advance than Polymorphic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

10 Different types of Viruses BAMSHPPEMM

8 Stealth

A

Technique used to prevent the virus from being detected by the anti-virus software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

10 Different types of Viruses BAMSHPPEMM

9 Armored

A

Have a layer of protection to confuse a program or a person who’s trying to analyse it

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

10 Different types of Viruses BAMSHPPEMM

10 Hoax

A

Form of technical social engineering that attempts to scare our end users into taking some kind of undesirable action on their system

Not technically a virus but the hoax tricks people in to thinking there is a virus on your computer. The virus is subsequently placed on to the computer. (Social engineering)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

10 types of Virues

Name 10 Virus Types

A

Boot Sector – Multipartite
Armoured – Stealth
Programme – Encrypted
Ploymorphic – Metamorphic
Hoax - Macro

How well did you know this?
1
Not at all
2
3
4
5
Perfectly