The Malware Family Tree & Indicators of Compromise (IOCs) Explained
HELLO FRIENDS!!
WELCOME TO CYPHER LOG
We have successfully completed a week of learning cybersecurity I hope, I don't distract from this. actually writing this blog gives me momentum to learn every day,
Ok let's begin to see what I have learned today, in the past week we have seen about how we can protect our data from threats and in this week it's all about threats like the types of threat. Shall we start now.
Today we are going to see about the type of malware
Types of malware
There are 6 types of malware, we can see it one by one first starts with,
Virus
Actually virus is a small piece of code which attached itself to a legitimate program or file, it requires our action to spread to be more clear if opening an already infected file without knowing it was infected it can spread itself. This is how the virus works.
Worm
Worm is a standalone malicious program, unlike virus it doesn't need our action to spread or to infect the system it will automatically scan the system to see if there is any vulnerability they will start to infect.
If there is a sudden massive spike in network traffic and multiple systems showing the same infection simultaneously then we can confirm it as a worm.
Trojan horse
Trojan horse will act like a spy in systems and they look like a real one , like we seen in the last blog the organized crime groups will use this method to achieve their motive, this malware distinguished as legitimate, useful software
And it tricks the user to download it by making them think it's a legitimate app.
This is how the Trojan malware works.
Ransomware
Actually ransomware is like kidnapping someone and demanding money for them, attackers use this to encrypt a sensitive file of the user and demanding payments for the decryption key, and they send it to the system by making the user click the phishing email.
Spyware & key loggers
It will act like a spy but as an invisible spy without anyone knowing about that and it will monitor our activities like passwords.
It is often spread by a malicious insider or bundles with free software.
We can identify it through a hidden background process like an unusual network connection sending small packets of data to unknown servers.
Rootkit
As you think we can figure out what it will be by its name it actually plays a role as a kit of tools that are designed to hide the presence of other malware and it gives the attacker a deep root access to the system.
It is usually installed after an initial breach like if there is Trojan in our system then they can install it by this they can maintain persistence.
These are the types of malware now move into the next part which is indicators of compromise [ IOCs ].
Indicators of compromise [ IOCs ]
If we are investigating a malware incident we can't just say it as a virus we need to hunt for indicators of compromise to prove it.
These acts like footprints let me give an example for this, if there is a crime like a murder then the investigators will definitely look for traces especially fingerprint and footprint right that's what this indicators of compromise - IOCs.
And we need to collect some other things like find out how deep the infection goes.
There are common IOCs :
File hashes, malicious IP address, Registry keys and also unusual network ports.
That's it guys, I hope I make you guys understand it well let's see in other blogs.
Stay tuned for everyday learning cyber security series. if you think I said something mistakenly you can let me know in comments.
If you want study guide to learn more about this you can get through this site.

Comments
Post a Comment