Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Malware Development for Ethical Hackers

You're reading from   Malware Development for Ethical Hackers Learn how to develop various types of malware to strengthen cybersecurity

Arrow left icon
Product type Paperback
Published in Jun 2024
Publisher Packt
ISBN-13 9781801810173
Length 390 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Mr. Zhassulan Zhussupov Mr. Zhassulan Zhussupov
Author Profile Icon Mr. Zhassulan Zhussupov
Mr. Zhassulan Zhussupov
Arrow right icon
View More author details
Toc

Table of Contents (23) Chapters Close

Preface 1. Part 1: Malware Behavior: Injection, Persistence, and Privilege Escalation Techniques FREE CHAPTER
2. Chapter 1: A Quick Introduction to Malware Development 3. Chapter 2: Exploring Various Malware Injection Attacks 4. Chapter 3: Mastering Malware Persistence Mechanisms 5. Chapter 4: Mastering Privilege Escalation on Compromised Systems 6. Part 2: Evasion Techniques
7. Chapter 5: Anti-Debugging Tricks 8. Chapter 6: Navigating Anti-Virtual Machine Strategies 9. Chapter 7: Strategies for Anti-Disassembly 10. Chapter 8: Navigating the Antivirus Labyrinth – a Game of Cat and Mouse 11. Part 3: Math and Cryptography in Malware
12. Chapter 9: Exploring Hash Algorithms 13. Chapter 10: Simple Ciphers 14. Chapter 11: Unveiling Common Cryptography in Malware 15. Chapter 12: Advanced Math Algorithms and Custom Encoding 16. Part 4: Real-World Malware Examples
17. Chapter 13: Classic Malware Examples 18. Chapter 14: APT and Cybercrime 19. Chapter 15: Malware Source Code Leaks 20. Chapter 16: Ransomware and Modern Threats 21. Index 22. Other Books You May Enjoy

Evasion static detection

Signature detection is simple to circumvent but time-consuming. It is essential to avoid hardcoding values that can be used to uniquely identify the implementation into malware. As mentioned earlier, the code that will be presented throughout this chapter dynamically retrieves or calculates the values.

Practical example

Let’s learn how to circumvent Microsoft Defender’s static analysis engine using XOR encryption and function call obfuscation tricks. At this stage, the payload is simply a pop-up Hello World message box. Therefore, we will place particular emphasis on static/signature evasion.

To encrypt the hello.bin payload and obfuscate functions, we can use the following Python script:

import sys
import os
import hashlib
import string
## XOR function to encrypt data
def xor(data, key):
    key = str(key)
    l = len(key)
    output_str = ""
   ...
lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image