188
2 Computer Viruses, Malicious Logic, and Spyware
In turn, CLR data section contains two important segments: the metadata segment
and the intermediate language (IL) code segment.
Metadata contains information related to the build, including the build manifest.
The manifest provides detailed description of the build, including the unique identifier (using hash, version number, etc.), information about the exported components, extended information about the type (supported by the Common Type
System—CTS), external links, and the list of files in the build. CLR widely uses
metadata.
Intermediate Language Code (IL) is an abstract language-independent code that
meets the requirements of the Common Intermediate Language (CIL) .NET CLR.
The term “intermediate” refers to the nature of the IL code, which is characterized by
cross-language and cross-platform compatibility. This intermediate language, which
is similar to the Java bytecode, allows platforms and languages to support the common
.NET CLR environment. IL supports object-oriented programming (polymorphism,
inheritance, abstract types, etc.), exceptions, events, and various data structures.
2.7.2 Main Methods of Injecting Software Trojans into PE
Files
The work [17] contains analysis of several most popular methods used to place
malicious data in PE files. In order to understand the presented material, the reader
needs to have at least medium understanding of the assembler for the x86 architecture,
debuggers, and the concept of PE files. This document was posted on December 8,
2016 on the pentest blog website and prepared in the PDF format for offline reading.
Here, we will only cite its basic provisions, which are most clearly presented in
[18–21].
All security and malware analysis specialists deal with backdoors on a daily basis.
Introducing a Trojan into the system or a specific program is the most popular way
to maintain constant access to the target machine. Most articles describe methods
of implanting malware in 32-bit PE files; however, as the PE format is a modified
version of Unix COFF (Common Object File Format), the logic embedded in these
techniques is also applied to all other types of executables. Moreover, invisibility
of an embedded software Trojan is extremely important; it influences directly its
lifetime in the system. The methods described below [18–22] are aimed at reducing
the percentage of Trojan detections to the lowest possible value.
First of all, we need to establish the terminology used further in the text; to do
this, let us define four basic concepts.
Training intrusion
Data security specialists are aware of the existence of entire group of “white” hackers
(white hats), who attack the digital structure of an organization like a real intruder
would do for the sole purpose of testing resistance of this system to various potential
external hazards (this process is also known as penetration testing). For example,
2 Computer Viruses, Malicious Logic, and Spyware
In turn, CLR data section contains two important segments: the metadata segment
and the intermediate language (IL) code segment.
Metadata contains information related to the build, including the build manifest.
The manifest provides detailed description of the build, including the unique identifier (using hash, version number, etc.), information about the exported components, extended information about the type (supported by the Common Type
System—CTS), external links, and the list of files in the build. CLR widely uses
metadata.
Intermediate Language Code (IL) is an abstract language-independent code that
meets the requirements of the Common Intermediate Language (CIL) .NET CLR.
The term “intermediate” refers to the nature of the IL code, which is characterized by
cross-language and cross-platform compatibility. This intermediate language, which
is similar to the Java bytecode, allows platforms and languages to support the common
.NET CLR environment. IL supports object-oriented programming (polymorphism,
inheritance, abstract types, etc.), exceptions, events, and various data structures.
2.7.2 Main Methods of Injecting Software Trojans into PE
Files
The work [17] contains analysis of several most popular methods used to place
malicious data in PE files. In order to understand the presented material, the reader
needs to have at least medium understanding of the assembler for the x86 architecture,
debuggers, and the concept of PE files. This document was posted on December 8,
2016 on the pentest blog website and prepared in the PDF format for offline reading.
Here, we will only cite its basic provisions, which are most clearly presented in
[18–21].
All security and malware analysis specialists deal with backdoors on a daily basis.
Introducing a Trojan into the system or a specific program is the most popular way
to maintain constant access to the target machine. Most articles describe methods
of implanting malware in 32-bit PE files; however, as the PE format is a modified
version of Unix COFF (Common Object File Format), the logic embedded in these
techniques is also applied to all other types of executables. Moreover, invisibility
of an embedded software Trojan is extremely important; it influences directly its
lifetime in the system. The methods described below [18–22] are aimed at reducing
the percentage of Trojan detections to the lowest possible value.
First of all, we need to establish the terminology used further in the text; to do
this, let us define four basic concepts.
Training intrusion
Data security specialists are aware of the existence of entire group of “white” hackers
(white hats), who attack the digital structure of an organization like a real intruder
would do for the sole purpose of testing resistance of this system to various potential
external hazards (this process is also known as penetration testing). For example,
