Login Register






Fileless Malware filter_list
Author
Message
Fileless Malware #1
Is anybody here that tried to develop such malware?
I am curious about it, because I find it pretty interesting and never actually tried to code a full fileless malware.
[Image: iQDVDdD.gif]

Reply

RE: Fileless Malware #2
Generally speaking, Ram Is volatile, so It's only as effective as the system uptime for the given session.

It'll be Interesting to perform a memory acquisition and analyze the memory dump file thereafter.
[Image: AD83g1A.png]

Reply

RE: Fileless Malware #3
Yeah, it gets interesting when you get into it.
You have to have everything in-memory and code in a way that you wouldn't touch the file system.
The easiest is to create a stager DLL, take the bytes and load it using powershell, psexec or craft your own loader.
The biggest drawback of having everything in memory is that you lose control after the target reboots his machine.

Reply

RE: Fileless Malware #4
(10-13-2018, 03:54 PM)Pikami Wrote: The biggest drawback of having everything in memory is that you lose control after the target reboots his machine.

I think you could use WMI for that, since it can auto-run programs stealthy on startup or based on specific events. Even though I think that may leave some forensics evidence on the HD, but not enough that could affect you.
[Image: iQDVDdD.gif]

Reply

RE: Fileless Malware #5
(10-13-2018, 03:50 PM)mothered Wrote: Generally speaking, Ram Is volatile, so It's only as effective as the system uptime for the given session.

Yeah generally with this kind of malware you do your thing and then you're out. However I think you can develop ways to make persistence possible.
[Image: iQDVDdD.gif]

Reply

RE: Fileless Malware #6
(10-13-2018, 04:07 PM)Cr3aTor Wrote:
(10-13-2018, 03:54 PM)Pikami Wrote: The biggest drawback of having everything in memory is that you lose control after the target reboots his machine.

I think you could use WMI for that, since it can auto-run programs stealthy on startup or based on specific events. Even though I think that may leave some forensics evidence on the HD, but not enough that could affect you.

Yeah, but than what's the point of making it file-less if you plan to leave a trace?
You would generally use this kind of malware in a risky environment to leave as little evidence as possible.

Reply

RE: Fileless Malware #7
Probably one of the reasons to go file-less is because it might side-step traditional AV detection methods that are focussed on scanning files on disk and also because it is inherently anti-forensic. If you don't leave anything on disk and/or if there's no execution artifact, it becomes a bit harder to even detect that something malicious slipped into the system if your system was not designed to handle things like detecting event consumers firing off from event filters from the WMI. If you combine this with LOL and actually never write to disk while performing malicious activity, pretty much most, if not all, of disk forensics flies out the window. The incidence response team must now be forced to handle everything in memory and it becomes much more riskier for them. If you can add even more anti-forensic capabilities into your kit, you could probably just nuke the system and peace out if you think someone is trying to acquire memory, destroying significant evidence and footprints which might as well stop the forensic investigation dead in its tracks.

Just some thoughts... Wink

Reply

RE: Fileless Malware #8
(10-13-2018, 04:12 PM)Cr3aTor Wrote: However I think you can develop ways to make persistence possible.

The only other possibility I can think of, Is to have the malware "directly" Infect and remain In the Registry (Windows-based) without writing to disk.

It's still fileless (diskless), but rather resides In the Registry and not Ram/Memory.
[Image: AD83g1A.png]

Reply