Please enable JavaScript.
Coggle requires JavaScript to display documents.
Malware Advanced Techniques (Rootkits (Rootkit Payloads (Adware/Spyware,…
Malware Advanced Techniques
Rootkits
Mode
Kernel Mode
Easy to detect
Diff. to write
User Mode
Difficult to detect
Easy to write
Some are anti theft mechanism. Not all are malicious
Rootkit Payloads
Adware/Spyware
Backdoors
Botnet
Software Technique to hide other softwares
Used to escalate privileges
Polymorphism
Use Encryption: They use diff. keys every time they infect. Virus loader has the decryption key
Signature keeps changing
Armored Virus
: Prevents Reverse Engineering
Methods
Prevent sandboxes
Block Access to Logs
Writing in assmebly language