190
2 Computer Viruses, Malicious Logic, and Spyware
4. Recovery of the execution thread.
Each of these steps has its own problems and nuances, which directly affect
the stability, life cycle, and invisibility of embedded malware, which will be
demonstrated below.
2.7.3 Solution to the Problem of Finding Available Space
for the Trojan Code
Finding available space is the first step to implementation of our task. It is extremely
important to select a correct place inside the PE file for introduction of a software
backdoor. Assessment of the threat on the side of the infected file greatly depends
on how you solve this task. Two approaches can be applied here.
The first consists in adding a new section. As compared to the second approach,
the probability of detection of the Trojan is higher here. Although, on the other hand,
we are not limited by space when adding a new section, therefore, we can introduce
a Trojan of any size (any level of complexity).
Using a disassembler of the LordPE editor, it is possible to extend a PE file, adding
a new section header. Figure 2.36 shows the table of sections of a putty executable.
PE editor was used to add a new 1000-byte new section NewSec.
When creating a new section, it is necessary to set flags for
reading/writing/execution in order to launch the shellcode when the PE image
is mapped into the memory.
After adding the section header, the intruder needs to adapt the file size, which is
done in the hex editor by adding empty bytes with the size of the new section to the
end of the file (Figs. 2.37 and 2.38).
After adding a new empty section, it is necessary to run the executable and check
it for mistakes. If everything goes well, the new section is ready for modification in
a debugger (Fig. 2.39).
Of course, solution to the available space problem by means of adding a new
section has certain disadvantages. Virtually, all antiviruses identify non-standard
Fig. 2.36 Table of sections
Précédent

- 211/839

Suivant