192
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.40 Results of verification of an executable with new empty section
sections; if such section also contains a full set of flags for reading/writing/execution,
this situation looks even more suspicious for security experts (Fig. 2.40).
Even if we simply add a new section with full rights without a backdoor, some
antiviruses will already mark the executable as malicious.
The second approach consists in using code caves.
The second method aimed at solving the problem of available drive space uses code
caves from the target executables. Nearly, all compiled binary files have cold caves
that can be used for malware introduction. Code caves attract much less attention
as compared to new sections, since in this case already existing regular sections are
used. The additional and equally important advantage consists in the fact that the
size of the PE file doesn’t change after malware injection. However, this technology
has its flaws (Fig. 2.41).
The number and size of code caves depend on the specific files, but their overall
size in general will be smaller than in case of adding a new section. When using a
code cave, the backdoor code shall be kept as small as possible. The second flaw is
the set of flags. Since the execution will be redirected to wde cave, the section needs
to have execution rights. In the case of some shellcodes (which encode or obfuscate
Précédent

- 213/839

Suivant