Afrikaans
Akan
Albanian
Amharic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Portuguese (Portugal)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
Welcome to the Mahler lecture.
Let's dive in.
So what is Möller, the term malware is a combination of the words malicious and softer.
Basically, it's any software intentionally designed to cause damage to the software and or hardware
of a computer or a computer network.
Of course, when I'm saying computers, I'm referring to a wide range of devices from microcontrollers,
wearables such as smartwatches to mobile phones, tablets, consoles, personal PCs, servers and so
on.
What can Mallory do, depending on the purpose for which the malware was built?
It can do one or more of the following things.
Some malware can tamper or even destroy data.
In some rare cases, malware can even damage or destroy harder.
It can make systems vulnerable by creating vectors that can be then used by even more malware.
In some cases, malware can install other malware.
It can generate spam or create denial of service attacks.
It can also deplete the resources of the system and use these resources for malicious purposes, such
as denial of service attacks.
Last on our list, malware can be used to spy on users extracting confidential information about the
users.
In this lecture, we'll have a look at eight of the most common types of malware virus or Trojan horse,
malicious, both ransomware, spyware, adware and rootkit.
So let's start with the most widely known malware, the virus.
The easiest way to understand the computer virus is to make a parallel with the biological virus.
Let's take covid, for example.
covid, like any other virus, needs a host so that it can replicate itself in order for someone to
get infected.
Some kind of interaction with an infected person needs to happen, like, for example, a handshake,
staying in close proximity without a mask or touching something that the infected person touched.
Once the virus gets inside the person's system, it attaches itself to healthy human cells and uses
these cells to create other instances of the virus infecting even more cells.
A computer virus is a malicious program or code which works in pretty much the same way.
First, a computer virus requires a host program, which it needs to infect.
For example, a computer virus could infect the operating system, such as, for instance, Windows.
Second, a computer virus requires user action to transmit itself from one system to another.
Viruses cannot spread without some sort of action from a user like, for example, opening an infected
word document.
And third, similar to biological virus, a computer virus infects other programs, inserting its malicious
code.
Now that we know what the virus is, let's have a look at some types of viruses.
First, we have the polymorphic virus.
A polymorphic virus changes its code each time it replicates itself.
It does this to evade detection by antivirus programs.
Because of this reason, modern viruses are usually polymorphic.
Next, we have the boot sector piracy, this type of virus is triggered whenever the victim starts their
computer.
After that, we have the following Fekter virus, which inserts malicious code into executable files,
such as, for example, media player Word Excel or the operating system.
Another type is the browser highjacker, which alters certain web browser functions.
The other functions could, for example, automatically direct the user to malicious website.
Next on the list, we have the resident virus.
This type of virus inserts itself as part of the operating system and is loaded into memory whenever
the operating system load.
Next, we'll discuss about direct action virus.
This type of virus is triggered when the user executes a file containing the virus.
Otherwise, the virus remains dormant.
Yet another type is the macro virus.
Macro viruses are written in the same macro language used for softer applications such as word, PowerPoint
or Excel, these type of viruses spread when the victim opens an infected document, which often spread
via email attachments.
Last on our list is the multi-party virus.
This kind of virus infects and spreads in multiple ways.
For example, such a virus can infect both document files as well as operating system files.
Another famous type of malware is the computer worm.
What exactly is a worm, a computer worm?
It's a standalone, malicious program that self replicates in order to spread to other computers.
A worm can replicate itself without any human interaction and is a standalone program.
So a worm does not need the host.
Let's have a quick look at some warm types grouped by means of spreading.
First type is Internet terms, Internet worms.
Can the network using infected computers in order to find other vulnerable computers, if such a computer
is found, the worm will then attempt to connect and infect the vulnerable machine.
Next, we have e-mail worms which spread through email messages which contain malicious attachments
or links to malicious websites.
Yet another type is instant messaging worms, which spread by sending malicious links via instant messaging
applications.
Last on our list is the file sharing network Worms, which place a copy of themselves in a shared folder
and spread via peer to peer network.
Let's also have a brief look at the concrete computer worm example, Stuxnet, Stuxnet is a computer
worm first discovered in 2010.
It targeted the programmable logic controllers, which are industrial control systems used for industrial
processes such as the centrifuges used for separating nuclear material.
Stuxnet exploited several zero their abilities in Windows and infected over 200000 computers.
It is reported that Stuxnet caused over 1000 machines to physically degrade, ruining almost one fifth
of Iran's nuclear centrifuges.
Next, we'll discuss the Trojan horse malware.
Similar to the Trojan horse of the ancient Greek story, a Trojan horse or a Trojan is a deceptive malware
which misleads the user of its true intent.
Trojans usually spread through social engineering, for example, through malicious email attachments
or from malicious websites as opposed to viruses and worms.
Trojans do not attempt to propagate themselves.
Let's explore some Trojan types first on our list, we have the backdoor Trojan, which gives malicious
users remote control over the infected computer depending on the Trojan.
This enables cyber criminals to do things like send, receive and delete files, launch programs or
display data.
Backdoor Trojans are often used to create botnet that can be used for cyber criminal purposes.
Another type that's running on the victim's computer.
Next on our list is the Trojan banker, which, as you already probably guessed from the name, is designed
to steal credit card information or the credentials for online banking systems.
Yet another type is a Trojan distributed denial of service, or Trojan Horse, which is used to conduct
denial of service attacks against targeted Web applications.
You'll learn more about denial of service attacks in another lecture.
Now, let's talk about the Trojan downloader and the Trojan dropper, these Trojans are used to install
other malware in the infected machine, such as other Trojans or viruses.
That Trojan downloader basically downloads and installs other malware.
While the Trojan dropper contains other malware source code embedded inside of it, the dropper uses
embedded source code to install new mother on the infected computer.
Next, we have the Trojan fake antivirus, which pretends to be legitimate antivirus software.
They are usually designed to obtain money from their victim in return for detection and removal of threats,
even though the threats that they report are actually nonexistent.
After that, let's have a look at the Trojan ransom, this type of Trojan can modify data on the victim's
computer so that the victim cannot use the data anymore.
The cyber criminals will only restore the data after ransom money is paid.
Last on our list is the Trojans, by which, as the name implies, spies on the victim, for example,
it can do that by tracking the data entered via the keyboard, taking screenshots or getting a list
of the running applications.
Let's move on to the next malware, the malicious bot first in order to define what the malicious bodies
we have to know.
What the body's about is a software application that runs automated and repetitive tasks.
The most common use of pot is Web crawling in which both gather information from the Web.
Another type of boats are chad boats, which are used more and more recently.
These kind of boats are often used by organizations to automate part of the support offered to customers.
OK, now that we know what the boat is, we can have a look at the malicious spot.
As the name implies, it's a boat used for malicious purposes.
Malicious bots are usually self-propagating malware that infects computers.
These boats then are used for cyber criminal activities, multiple computers infected with malicious
bots can form a botnet or called botnet.
Botnet can have different types of architectures.
Some of the first botnet use the client server architecture in which the bots act as clients and connect
to a server also known as Command and Control Center.
The command and control center then issues commands to the bot.
The boards execute the commands, relayed the results back to the command and control center.
We can see an example of a client server architecture on the top right part of the slide in the middle.
We have the server, the command and control center and around it we have the clients.
The bot infected computers.
The main disadvantage of this type of botnet architecture is that if the command and control center
is compromised, the whole botnet can be potentially shut down.
Since the control center issues commands the whole botnet, a more resilient architecture is peer-to-peer.
This botnet do not have a centralized server and each bot behaves both this client, which receives
commands and a server which issues commands.
How does this work?
One way can be as follows.
Each bot searches the network for other bots, adding them to a contact list.
When found, the owner of the botnet can issue commands from one of the bots and then the bot spreads
the command to its noncontact.
Then each of the contacts press the command further in order to make sure that the commands are genuine,
the owner of the botnet can use a secret key to digitally signed documents.
This way, the bots can verify that the command is indeed genuine.
We can see an example of a peer to peer botnet in the bottom right part of the slide, each computer
in the diagram is infected with the bot.
In the diagram, we can see that we do not have the central server anymore and that each bot has several
connections to other bots in the botnet.
Now let's explore some malicious types.
First, we have the spambots, which, as the name implies, are designed to propagate spam emails or
messages.
Another type is distributed denial of service spots or dead spots, which are used to initiate distributed
denial of service attacks against specific targets, you will learn more about this type of attack and
the denial of service lecture.
Next on our list is registration.
But these are not your specific email addresses to sign the victim up to numerous services in order
to flood their email inbox.
This can be used to distract from important messages such as a security breach.
Now let's talk about malicious websites, crappers.
Besides legitimate purposes, websites, crappers can also be used maliciously.
For example, malicious websites crappers can be used to obtain the content of websites in order to
create malicious copies of said websites.
Related to this, there are bots that crap the Internet for information about individuals.
For example, such a bot could scrap information from social media such as LinkedIn and Facebook so
that cyber criminals can use this information to prepare spearfishing attacks.
Other types of bots can open back doors on the infected computers so that even more malware can be installed.
Last on our list, we have your boats, which are used to generate fake views, comments and likes on
the Internet.
It's a concrete example of a botnet and a Trojan.
We will talk about emoted.
Emoted is a malware which was first detected in 2014.
It started as a banking Trojan that was designed to steal banking credentials and that evolved into
a downloader Trojan used to install other malware, then Emoted was also configured as a botnet, delivering
malware as a service to cyber criminals.
The cyber criminals using emoted could, for example, obtain banking credentials of victims using malware
or installed ransomware on infected computers.
And what that spread through spam emails.
The emails contained infected attachments such as malicious word documents that contained the malware.
Recently, it even used the fear of covid to spread itself via spam emails pretending to educate victims
about covid emoted was one of the most active and dangerous threats.
Up until recently, Emoted has suffered a major disruption in January 2021, after a major collaborative
effort from international police, police has captured several hundred servers around the world, which
were used to manage infected computers, spread the malware, surf cyber criminal groups and improve
emoted.
Next on the malware list is ransomware.
Ransomware is a type of malware that threatens its victims with blocking access to the data or threatens
them with publishing confidential data on the Internet unless a ransom is paid to the attackers.
The most common types of ransom are encrypting ransomware, known, encrypting ransomware and exfiltration.
The encrypting ransomware basically encrypts the victim's data, making it unavailable to anyone.
Then the cyber criminals behind the ransomware ask for a ransom in order to provide the decryption key
to the victim using the decryption key.
In theory, the victim can decrease the data and have access to it again.
However, be aware that even if the victim pays, there is no guarantee that the cyber criminals will
actually provide the decryption key.
The second type is not encrypted ransomware, also known as Calver.
This is a less dangerous malware which just pretends that it has encrypted the victim's data.
For example, such careworn can display an image on the victim's computer saying that the files have
been encrypted by ransomware.
This would be done in order to scare the victim into paying the ransom.
However, in case of Scherba, the victim's data is still intact.
Last type is exfiltration or neckwear.
This type of ransomware threatens to leak online personal data of the victim, such as, for instance,
private pictures or private conversations unless a ransom is paid.
However, similar to encrypting ransomware, the victim has no guarantee that the attacker won't leak
the data anyway.
Let's have a quick look at the concrete example of ransomware.
One is an encrypted ransomware, which was first discovered in May 2017.
One is an encrypted ransomware, which was first discovered in May 2017.
It spread through the Internet using an exploit named Internal Blue, which targeted Windows operating
systems.
The internal blue exploit was allegedly leaked from the US National Security Agency, even though Microsoft
released a patch in March 2017 that fixed the vulnerability exploited by one Akroyd in May 2017, one
crisis still spread to over two hundred and thirty thousand unpatched computers around the world.
You can see on the left side a picture with the countries affected by the initial want to attack.
The affected countries are colored in red.
One impacted many companies and organizations such as the Spanish Telecom, Telefonica and the British
National Health Service, impacting multiple hospitals which had to turn away patients and cancel scheduled
operations.
One Okri also infected FedEx, Deutsche Bank, Honda, Renault, the Russian Interior Ministry and the
Russian Telecom Megafaun.
The original attack of one Okri was stopped a few days later after a killswitch was found, which prevented
one aircraft from spreading further.
Next, we'll talk about spyware.
Spyware is malware that infects devices in order to gather information about its victims.
For instance, depending on the spyware, it can gather information such as credentials to different
websites, browser history, a list of applications installed, emails sent and received, the input
introduced from the keyboard or credit card information.
Next on our list is Adver Adwar stands for advertising supported software and is basically software
that is designed to generate ads.
Adwar can also encourage users to install additional software promoted by third party users.
Adwar is not necessarily mahrer.
It can be used in legitimate use cases in which developers obtain extra income from ads.
These ads can be embedded in their websites or applications.
There are also other types of hardware which can be potentially unwanted applications.
First, we have legal but abusive or deceptive adver.
These type of Adwar might make it difficult for the user to opt out of installing additional software.
Also in this category we might have Adwar, which displays ads that might be direct to malicious websites.
In these cases, the creator of the Adwar might not be aware of the malicious third party ads.
Another type of abusive but legal.
Adwar is Adwar that produces excessive.
At an example of such, Adwar can be a browser toolbar that bombards you with ads.
Finally, we have illegal, malicious software in which the Adwar intentionally distributes malware
or links to malicious websites.
This type of hardware is often accompanied by spyware.
Last on our list is rootkit.
The term rootkit is a combination of the word truth, which is the name of privileged account in Unix
like operating systems, and the work kit, which refers to the collection of software that implements
all a rootkit, is a set of software tools used to gain privileged access or control over a host.
It is usually classified as malware, since it's often used for malicious purposes.
Malicious rockets are designed to stay hidden and conceal themselves as well as other malware.
There are, however, some legitimate utilities using rootkit, for example, some applications that
emulate hardware or software or some applications that are used to detect cheating in online games.
With that, we conclude the exploration of different types.
Before we wrap up, let's have a look at the malware metrics, you might have already noticed that some
types of malware can overlap.
To better understand the relations between different types, today, we will explore the following malware
matrix.
A virus cannot be worm y because a virus requires a host, while a worm, which is a standalone program
that's not a virus, cannot be a Trojan either because the virus can replicate itself, while a Trojan
cannot be says that a virus can be a malicious both ransomware, spyware, adware and finally can use
a rootkit to gain privileged access and or conceal itself.
Next, let's have a look at the computer worm.
As we discussed, it cannot be a virus.
Also, a worm cannot be a Trojan horse because a worm can self replicate while a Trojan cannot again.
Besides that, a worm can be any other type of malware, such as a bot, ransomware, spyware, adware,
and similarly to the virus, it can use a rootkit to gain privileged access.
After the warm let's talk about Trojan, as we already mentioned, a Trojan cannot be a virus or a worm,
but similarly to the worm and virus, it can be other types of malware, such as both ransomware, spyware,
adware and rootkit.
Next on the metrics, we have the malicious bot, which can also be any other type of malware.
After that, we have ransomware, which similarly can be any other type of malware.
One small note for ransomware.
While technically possible, it does not make much sense for a ransomware to also be a nightmare.
Next, we have spyware, which can also be any other type of malware discussed today.
After that, we have a look at that.
Similarly, it can be any other type of malware discussed today with the note that for Adwar, it does
not make much sense to also be ransomware.
Last, we have the rootkit which can be used by any other type of malware to discuss today in order
to gain privileged access and or conceal the malware.
I hope that after discussing this matrix, you now have a better understanding of relationships between
different types of malware discussed today.
To recap, in this lecture, we learn what mulberries, what it can do.
We explore the most common types of malware, looking at their capabilities and some concrete examples.
Finally, we had a look at the malware metrics to better understand the relationship between different
types of malware.
With that, we conclude this lecture.
If you have any questions, don't hesitate to ask us.
See you soon in the next lecture.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.