2.7 Example of Injection of a Software
195
after altering privileges of the section, the first stage of malware injection can be
considered complete. Now, we need to redirect execution to our field.
2.7.4 Interception of the Current Execution Thread
During this stage, it is necessary to redirect the execution thread to the backdoor
code by modifying the required instruction in the executable. Here, it is necessary to
mention an important detail concerning selection of the instruction to be changed.
All binary instructions have their size in bytes. Switching to the backdoor location
address will require a long jump using five or six bytes. If a binary file is changed,
the instruction to be patched must be of the same size as the long jump; otherwise,
the following and the preceding instructions will be corrupted.
It is extremely important to select a correct place for redirection of execution,
since if the redirection is performed directly, the detection by antivirus products at
the stage of dynamical analysis is inevitable.
Let us consider the possible ways of masking inside user functions.
The first way of bypassing the sandbox and dynamical analysis that comes to
mind is delayed execution of the shellcode or application of the sandbox detector,
the results of operation of which initiate execution of certain algorithm branches. On
the other hand, due to limited code size, we cannot add extra sections of the code into
the PE file in most cases. Moreover, implementation of anti-detection techniques at
a low level requires a lot of time and efforts.
This method employs the functions requiring activity from the user. Redirection
of execution inside such functions will be triggered only if the user is working in
the program. If such technique is implemented correctly, success will be practically
guaranteed; in addition, the size of the backdoor will not be increased.
Pressing the Open button from the graphical shell will start the function of
verification of the set IP address (Fig. 2.43).
If the IP address field is not empty and the value is correct, the function is launched
to connect to the specified IP address.
If the client has successfully created an ssh session, a new window for entering
the username and password will be displayed (Fig. 2.44).
Redirection will take place at this point. Since antivirus products are not advanced
enough for analysis of such mechanisms, the embedded backdoor will most likely
remain undetected by the dynamic analysis.
Simple methods of reverse engineering designed for work with strings and references to strings will help easily find the connection function address after the client
establishes connection with the designated IP address.
The line “login as:”, which appears in a popup window, will help us find the
address of the connection function. IDA Pro will help us find references to strings.
In order to find the string “login as”, use Views-> Open Subviews-> Strings on
IDA in IDA Pro.
195
after altering privileges of the section, the first stage of malware injection can be
considered complete. Now, we need to redirect execution to our field.
2.7.4 Interception of the Current Execution Thread
During this stage, it is necessary to redirect the execution thread to the backdoor
code by modifying the required instruction in the executable. Here, it is necessary to
mention an important detail concerning selection of the instruction to be changed.
All binary instructions have their size in bytes. Switching to the backdoor location
address will require a long jump using five or six bytes. If a binary file is changed,
the instruction to be patched must be of the same size as the long jump; otherwise,
the following and the preceding instructions will be corrupted.
It is extremely important to select a correct place for redirection of execution,
since if the redirection is performed directly, the detection by antivirus products at
the stage of dynamical analysis is inevitable.
Let us consider the possible ways of masking inside user functions.
The first way of bypassing the sandbox and dynamical analysis that comes to
mind is delayed execution of the shellcode or application of the sandbox detector,
the results of operation of which initiate execution of certain algorithm branches. On
the other hand, due to limited code size, we cannot add extra sections of the code into
the PE file in most cases. Moreover, implementation of anti-detection techniques at
a low level requires a lot of time and efforts.
This method employs the functions requiring activity from the user. Redirection
of execution inside such functions will be triggered only if the user is working in
the program. If such technique is implemented correctly, success will be practically
guaranteed; in addition, the size of the backdoor will not be increased.
Pressing the Open button from the graphical shell will start the function of
verification of the set IP address (Fig. 2.43).
If the IP address field is not empty and the value is correct, the function is launched
to connect to the specified IP address.
If the client has successfully created an ssh session, a new window for entering
the username and password will be displayed (Fig. 2.44).
Redirection will take place at this point. Since antivirus products are not advanced
enough for analysis of such mechanisms, the embedded backdoor will most likely
remain undetected by the dynamic analysis.
Simple methods of reverse engineering designed for work with strings and references to strings will help easily find the connection function address after the client
establishes connection with the designated IP address.
The line “login as:”, which appears in a popup window, will help us find the
address of the connection function. IDA Pro will help us find references to strings.
In order to find the string “login as”, use Views-> Open Subviews-> Strings on
IDA in IDA Pro.
