Section 6.47 Viruses Flashcards
Objectives 2.4 Given a Scenario, analyse indicators of malicious activity
Viruses
Made up of malicious code that’s run on a machine without the user’s knowledge and this allows the code to infect the computer whenever it has been run
10 Different types of Viruses BAMSHPPEMM
1 Boot Sector
One that is stored in the first sector of a hard drive and is then loaded by the bootstrap loader into memory whenever the computer boots up
Hard to detect need specific anti virus that looks for boot sector during the boot up process of a computer
10 Different types of Viruses BAMSHPPEMM
2 Macro
Form of code that allows a virus to be embedded inside another
document so that when that document is opened by the user, the virus is executed
Macros are used in software like excel and is normally fine. However this code can be manipulated by attackers
10 Different types of Viruses BAMSHPPEMM
3 Program
Attackers try to find executables or application files to infect with their malicious code
Virus that tries to install itself on prgrammes and application like Word.
10 Different types of Viruses BAMSHPPEMM
4 Multipartite
Combination of a boot sector type virus and a program virus. Able to place itself in the boot sector and be loaded every time the computer boots. It can install itself in a program where it can be run every time the computer starts up
Cyber Security analysts can easily miss the boot aspect of the virus and only clean up the program virus.
10 Different types of Viruses BAMSHIPPEM
5 Encrypted
Designed to hide itself from being detected by encrypting its malicious code or payloads to avoid detection by any antivirus software
Malicious code is scrambled in to cyper text
10 Different types of Viruses BAMSHPPEMM
6 Polymorphic
Advanced version of an encrypted virus, but instead of just encrypting the contents it will actually change the viruses code each time it is executed by altering the decryption module in order for it to evade detection
Morph the way the code looks so that its signature based anti-virus applications are not going to detect it as being malicious
10 Different types of Viruses BAMSHPPEMM
7 Metamorphic
Able to rewrite themselves entirely before it attempts to infect a given file
More advance than Polymorphic
10 Different types of Viruses BAMSHPPEMM
8 Stealth
Technique used to prevent the virus from being detected by the anti-virus software
10 Different types of Viruses BAMSHPPEMM
9 Armored
Have a layer of protection to confuse a program or a person who’s trying to analyse it
10 Different types of Viruses BAMSHPPEMM
10 Hoax
Form of technical social engineering that attempts to scare our end users into taking some kind of undesirable action on their system
Not technically a virus but the hoax tricks people in to thinking there is a virus on your computer. The virus is subsequently placed on to the computer. (Social engineering)
10 types of Virues
Name 10 Virus Types
Boot Sector – Multipartite
Armoured – Stealth
Programme – Encrypted
Ploymorphic – Metamorphic
Hoax - Macro