Question some questions about viruses, miners, antiviruses and encryptors

Help answer the author's question with clear explanations and useful steps.
Yes, there are various subtypes of viruses such as Trojans, worms, ransomware, adware, etc. Viruses bypass antivirus checks using methods like polymorphism (changing their code to avoid detection), exploiting software vulnerabilities, or disguising as legitimate programs.
 
Hi, I have a few questions and I’d really appreciate some clarification:

1. About miners: If you keep the Task Manager open in the background for a long time, will a miner process be able to detect that it’s just running in the background and that nobody is actively checking it?

2. About antiviruses: How do antivirus databases work? How exactly do they detect malware — for example, do they compare the code to specific known malware signatures in the database?

3. About encryptors: How do they work, and what are the different types of data encryption?

I’m asking all of this to better understand how these systems work in practice. Thank you in advance!
 
Last edited:
1. About miners: If you keep the Task Manager open in the background for a long time, will a miner process be able to detect that it’s just running in the background and that nobody is actively checking it?
Miners generally detect Task Manager and pause till it is opened. You might have a better luck with Process Explorer or System Informer.
2. About antiviruses: How do antivirus databases work? How exactly do they detect malware — for example, do they compare the code to specific known malware signatures in the database?
Yes, but all hackers have to do, is to change one line of code and it gets a new signature, thus AVs also rely on heuristics, checking for malware like behavior.
3. About encryptors: How do they work, and what are the different types of data encryption?
It all starts with scripts via CMD, WSH, PowerShell. Ransomware gains SYSTEM privileges and then encrypts data using bitlocker or it's own encryption.


Fileless malware.png
 
Майнери зазвичай виявляють диспетчер завдань і зупиняються, доки він не буде відкрито. Можливо, вам більше пощастить з Process Explorer або System Informer.

Так, але все, що потрібно зробити хакерам, це змінити один рядок коду, і він отримає новий підпис, тому антивіруси також покладаються на евристику, перевіряючи наявність поведінки, подібної до шкідливого програмного забезпечення.

Все починається зі скриптів через CMD, WSH, PowerShell. Програма-вимагач отримує системні привілеї, а потім шифрує дані за допомогою Bitlocker або власного шифрування.

[URL-адреса розгортається="true"]https://dmcxblue.net/2021/08/30/fileless-malware/[/URL-адреса]

View attachment 288916
Thanks for all this information
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top