This chapter presents a set of questions and exercises focused on malware and its use in cybercriminal activities and offensive operations. The problems are organized into two sections to facilitate a structured exploration of the topic. The first section addresses some of the techniques and mechanisms employed by modern malware, including multi-stage payloads, packing and morphisms, Living-Off-The-Land (LOTL) strategies, and Command & Control (C2) infrastructures. This section also introduces classic malware terminology, such as logic bombs, worms, backdoors, and rootkits, alongside foundational theoretical concepts in malware research, including the undecidability of the computer virus detection problem and the “trusting trust” dilemma. The second section is dedicated to short malware analysis exercises. Here, the focus is on examining specific code samples to explore aspects such as the functionalities they provide, their potential impact on target systems, and possible defense strategies. These problems aim to enhance critical thinking and practical analysis skills, enabling readers to better understand the evolving threat landscape and the methodologies used in malware analysis.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Malware

  • Juan Tapiador

摘要

This chapter presents a set of questions and exercises focused on malware and its use in cybercriminal activities and offensive operations. The problems are organized into two sections to facilitate a structured exploration of the topic. The first section addresses some of the techniques and mechanisms employed by modern malware, including multi-stage payloads, packing and morphisms, Living-Off-The-Land (LOTL) strategies, and Command & Control (C2) infrastructures. This section also introduces classic malware terminology, such as logic bombs, worms, backdoors, and rootkits, alongside foundational theoretical concepts in malware research, including the undecidability of the computer virus detection problem and the “trusting trust” dilemma. The second section is dedicated to short malware analysis exercises. Here, the focus is on examining specific code samples to explore aspects such as the functionalities they provide, their potential impact on target systems, and possible defense strategies. These problems aim to enhance critical thinking and practical analysis skills, enabling readers to better understand the evolving threat landscape and the methodologies used in malware analysis.