Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Malware Development for Ethical Hackers

You're reading from   Malware Development for Ethical Hackers Learn how to develop various types of malware to strengthen cybersecurity

Arrow left icon
Product type Paperback
Published in Jun 2024
Publisher Packt
ISBN-13 9781801810173
Length 390 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Mr. Zhassulan Zhussupov Mr. Zhassulan Zhussupov
Author Profile Icon Mr. Zhassulan Zhussupov
Mr. Zhassulan Zhussupov
Arrow right icon
View More author details
Toc

Table of Contents (23) Chapters Close

Preface 1. Part 1: Malware Behavior: Injection, Persistence, and Privilege Escalation Techniques FREE CHAPTER
2. Chapter 1: A Quick Introduction to Malware Development 3. Chapter 2: Exploring Various Malware Injection Attacks 4. Chapter 3: Mastering Malware Persistence Mechanisms 5. Chapter 4: Mastering Privilege Escalation on Compromised Systems 6. Part 2: Evasion Techniques
7. Chapter 5: Anti-Debugging Tricks 8. Chapter 6: Navigating Anti-Virtual Machine Strategies 9. Chapter 7: Strategies for Anti-Disassembly 10. Chapter 8: Navigating the Antivirus Labyrinth – a Game of Cat and Mouse 11. Part 3: Math and Cryptography in Malware
12. Chapter 9: Exploring Hash Algorithms 13. Chapter 10: Simple Ciphers 14. Chapter 11: Unveiling Common Cryptography in Malware 15. Chapter 12: Advanced Math Algorithms and Custom Encoding 16. Part 4: Real-World Malware Examples
17. Chapter 13: Classic Malware Examples 18. Chapter 14: APT and Cybercrime 19. Chapter 15: Malware Source Code Leaks 20. Chapter 16: Ransomware and Modern Threats 21. Index 22. Other Books You May Enjoy

Time-based sandbox evasion techniques

Sandbox emulation is typically brief because sandboxes are typically filled with thousands of samples. Rarely does emulation time exceed three to five minutes. Malware can, therefore, take advantage of this fact to avoid detection by delaying its malicious actions for an extended period of time.

Sandboxes can incorporate features that manipulate time and execution delays to counteract this. Cuckoo Sandbox, for instance, has a sleep-skipping feature that replaces delays with a very brief value. This should compel the malware to initiate its malicious behavior prior to the expiration of the analysis timer.

A simple example

Delaying execution may circumvent sandbox analysis by exceeding the sample execution’s duration limit. Nonetheless, it is not as simple as Sleep(1000000).

We can check the uptime of the system before and after sleeping. Additionally, we can use a lower-level userland API for sleeping (there is a slightly smaller...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime