Question Will Kaspersky's network monitor catch suspicious activity in time?

Kaspersky
45 Replies 5,616 Views
Help answer the author's question with clear explanations and useful steps.

Studynxx

Level 9
Verified
Well-known
I'm learning Wireshark for malware analysis. I'm watching a guy's video on analyzing malware with Wireshark for suspicious traffic. Let's say you have Kaspersky installed and your sample is trying to sniff and then send HTTP POST requests with the sniffed credentials (login data) to some random IP in Russia or something. Would Kaspersky catch this and stop it from happening without quarantining the software? Or what would happen?
 
Kaspersky, like any other AV blocks connections to malicious domains. When Kaspersky analyses samples, it uses static and dynamic analysis to extract URLs and domains. They also use other methods to discover malicious sites and potentially, some third party feeds.

In addition, Kaspersky uses behavioural analysis (like all AVs), static and dynamic malware analysis, heuristics and virtually any protection method known has been deployed by Kaspersky. Their Application Control (IDS) is bespoke.

Kaspersky has a very light implementation of IPS — it is not a full blown deep packet inspection method that constantly scans the traffic for signs of attacks.

Kaspersky is not some sort of a miracle in the cybersecurity world and is vulnerable to the following:

  • Users disabling Kaspersky protection methods thinking the detection is just another detection on cracks.
  • When software has been executed knowingly by happy clickers and people looking to save money on apps, this opens risks. Kaspersky, like all AVs performs behavioural monitoring in asynchronous mode. It is possible that whilst Kaspersky captures and scans the behaviour, a sophisticated and quick “Smash and Grab” attack already exfiltrates credentials, and only then Kaspersky reacts.
  • The network protection relies on the domains either being too new (which would be the case when domain generation algorithms are used) or being old and known malicious. But it’s possible that attackers can create domains, leave them dormant to mature and at one point launch an attack. The domain is neither new nor it is known malicious.
  • Even if Kaspersky had full blown IPS based on signatures (or IPS has been deployed for example on the router) this method is rather reactive, relies mostly on signatures and traffic patterns. Whilst it is a nice to have feature, it’s not a panacea that will completely block attackers.
In Essence, Kaspersky needs to be combined with good habits.
 
Kaspersky, like any other AV blocks connections to malicious domains. When Kaspersky analyses samples, it uses static and dynamic analysis to extract URLs and domains. They also use other methods to discover malicious sites and potentially, some third party feeds.

In addition, Kaspersky uses behavioural analysis (like all AVs), static and dynamic malware analysis, heuristics and virtually any protection method known has been deployed by Kaspersky. Their Application Control (IDS) is bespoke.

Kaspersky has a very light implementation of IPS — it is not a full blown deep packet inspection method that constantly scans the traffic for signs of attacks.

Kaspersky is not some sort of a miracle in the cybersecurity world and is vulnerable to the following:

  • Users disabling Kaspersky protection methods thinking the detection is just another detection on cracks.
  • When software has been executed knowingly by happy clickers and people looking to save money on apps, this opens risks. Kaspersky, like all AVs performs behavioural monitoring in asynchronous mode. It is possible that whilst Kaspersky captures and scans the behaviour, a sophisticated and quick “Smash and Grab” attack already exfiltrates credentials, and only then Kaspersky reacts.
  • The network protection relies on the domains either being too new (which would be the case when domain generation algorithms are used) or being old and known malicious. But it’s possible that attackers can create domains, leave them dormant to mature and at one point launch an attack. The domain is neither new nor it is known malicious.
  • Even if Kaspersky had full blown IPS based on signatures (or IPS has been deployed for example on the router) this method is rather reactive, relies mostly on signatures and traffic patterns. Whilst it is a nice to have feature, it’s not a panacea that will completely block attackers.
In Essence, Kaspersky needs to be combined with good habits.
Is WireShark enough for analysis? Combined with VirusTotal?
 
Which would you rather have - an infected PC or a non-working malware?
Both are useless 😀
By the way, I shouldn't run them on a VM right? Since you said it's very common to use those if/if not switch case statements to check for VMs

They use algorithms to detect the VM (which I mentioned before as well).

For example, this detects number of installed apps:
C++:
#include <windows.h>

int getNumberOfInstalledApps() {
    HKEY hKey;
    LONG result = RegOpenKeyEx(HKEY_LOCAL_MACHINE, L"Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall", 0, KEY_READ, &hKey);

    if (result != ERROR_SUCCESS) {
        return -1;
    }

    DWORD numberOfSubKeys = 0;
    RegQueryInfoKey(hKey, NULL, NULL, NULL, &numberOfSubKeys, NULL, NULL, NULL, NULL, NULL, NULL, NULL);
    RegCloseKey(hKey);

    return static_cast<int>(numberOfSubKeys);
}
This checks for the number of recently used files
C++:
#include <windows.h>
#include <shlobj.h>
#include <vector>
#include <string>
#include <filesystem>

#pragma comment(lib, "Shell32.lib")

std::vector<std::wstring> getRecentDocuments() {
    std::vector<std::wstring> recentFiles;
    PWSTR recentItemsPath = NULL;

    HRESULT hr = SHGetKnownFolderPath(FOLDERID_Recent, 0, NULL, &recentItemsPath);

    if (SUCCEEDED(hr)) {
        try {
            for (const auto& entry : std::filesystem::directory_iterator(recentItemsPath)) {
                recentFiles.push_back(entry.path().filename().wstring());
            }
        } catch (const std::filesystem::filesystem_error& e) {
            // Intentionally left blank to handle errors gracefully
        }
    }

    if (recentItemsPath) {
        CoTaskMemFree(recentItemsPath);
    }

    return recentFiles;
}

Control function
C++:
int getSoftwareInventoryCount();
int getRecentActivityCount();

bool isSystemUsageAnomalous() {
    int softwareCount = getSoftwareInventoryCount();
    int activityCount = getRecentActivityCount();

    if (softwareCount >= 0 && softwareCount < 20 && activityCount >= 0 && activityCount < 5) {
        return true;
    }

    return false;
}

Then, they likely use one boolean variable (something like isVM) which will be set to 1 or true (depending on language both are possible and equal yes). The function that checks for VM artefacts will return true or false in the end.

Then, the algorithm goes like if isVM == true then {code} else {malicious behaviour} where code most often contains exit instructions.

You can also flip, if (!isVM) {code} else {malicious behaviour}. It’s all up to the programmer. Nothing is set in stone, that’s on C++ but it can be done on any language. Even on a simple VBA.
 
Last edited:
Both are useless 😀


They use algorithms to detect the VM (which I mentioned before as well).

For example, this detects number of installed apps:
C++:
#include <windows.h>

int getNumberOfInstalledApps() {
    HKEY hKey;
    LONG result = RegOpenKeyEx(HKEY_LOCAL_MACHINE, L"Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall", 0, KEY_READ, &hKey);

    if (result != ERROR_SUCCESS) {
        return -1;
    }

    DWORD numberOfSubKeys = 0;
    RegQueryInfoKey(hKey, NULL, NULL, NULL, &numberOfSubKeys, NULL, NULL, NULL, NULL, NULL, NULL, NULL);
    RegCloseKey(hKey);

    return static_cast<int>(numberOfSubKeys);
}
This checks for the number of recently used files
C++:
#include <windows.h>
#include <shlobj.h>
#include <vector>
#include <string>
#include <filesystem>

#pragma comment(lib, "Shell32.lib")

std::vector<std::wstring> getRecentDocuments() {
    std::vector<std::wstring> recentFiles;
    PWSTR recentItemsPath = NULL;

    HRESULT hr = SHGetKnownFolderPath(FOLDERID_Recent, 0, NULL, &recentItemsPath);

    if (SUCCEEDED(hr)) {
        try {
            for (const auto& entry : std::filesystem::directory_iterator(recentItemsPath)) {
                recentFiles.push_back(entry.path().filename().wstring());
            }
        } catch (const std::filesystem::filesystem_error& e) {
            // Intentionally left blank to handle errors gracefully
        }
    }

    if (recentItemsPath) {
        CoTaskMemFree(recentItemsPath);
    }

    return recentFiles;
}

Control function
C++:
int getSoftwareInventoryCount();
int getRecentActivityCount();

bool isSystemUsageAnomalous() {
    int softwareCount = getSoftwareInventoryCount();
    int activityCount = getRecentActivityCount();

    if (softwareCount >= 0 && softwareCount < 20 && activityCount >= 0 && activityCount < 5) {
        return true;
    }

    return false;
}

Then, they likely use one boolean variable (something like isVM) which will be set to 1 or true (depending on language both are possible and equal yes). The function that checks for VK artefacts will return true or false in the end.

Then, the algorithm goes like if isVM == true then {code} else {malicious behaviour} where code most often contains exit instructions.

You can also flip, if (!isVM) {code} else {malicious behaviour}. It’s all up to the programmer. Nothing is set in stone, that’s on C++ but it can be done on any language. Even on a simple VBA.
So VirusTotal's Behavior and Relations tabs aren't enough? They do get run in sandboxes. Do you think malware can detect those sandboxes as VMs?
 
So VirusTotal's Behavior and Relations tabs aren't enough? They do get run in sandboxes. Do you think malware can detect those sandboxes as VMs?
In some instances it can’t, in some instances it will be able to. These sandboxes take extra care and push the extra mile, they install high number of software, move the mouse, press buttons (whichever one users will logically press), when malware performs certain checks and calls, they return fictional results, they attempt to ignore long sleeps and perform push-forward emulation. Highly sophisticated malware that was really expensive to develop could potentially include logics that the sandbox may not be able to counteract. The sandbox static analysis will be still be useful in these cases.

For example, I can check current time online, then implement 5 min sleep and then again check the time online. If the code ran as I want it to run, then the time should be previousTime + 5 min. If not, then the long sleeps were ignored, it could be sandbox.

But when such sample is detected, the sandbox will be improved.

So it’s hard to say what will happen. It’s a cat and mouse game. In general, they are difficult to evade, much more difficult than an environment that you will setup.
 
In some instances it can’t, in some instances it will be able to. These sandboxes take extra care and push the extra mile, they install high number of software, move the mouse, press buttons (whichever one users will logically press), when malware performs certain checks and calls, they return fictional results, they attempt to ignore long sleeps and perform push-forward emulation. Highly sophisticated malware that was really expensive to develop could potentially include logics that the sandbox may not be able to counteract. The sandbox static analysis will be still be useful in these cases.

But when such sample is detected, the sandbox will be improved.

So it’s hard to say what will happen. It’s a cat and mouse game. In general, they are difficult to evade, much more difficult than an environment that you will setup.
1754427788022.png


Kaspersky Malware Analyst says it's not malware but this has me concerned especially the first 3 (top-down). Why would a crack cause these tactics to be detected? I'll delete all credentials, browser cookies, unmount network shares on my 2nd laptop and delete all entries from Credential Manager and install Wireshark and do analysis on an isolated network, I'm really curious what this crack does behind the scenes.
 
View attachment 290019

Kaspersky Malware Analyst says it's not malware but this has me concerned especially the first 3 (top-down). Why would a crack cause these tactics to be detected? I'll delete all credentials, browser cookies, unmount network shares on my 2nd laptop and delete all entries from Credential Manager and install Wireshark and do analysis on an isolated network, I'm really curious what this crack does behind the scenes.
Cracks often employ these analysis/checks because they don’t want their logics to be debugged and discovered, in this case the software developer will implement logics that will invalidate the crack. These logics awfully resemble what malware authors are doing and often, detection is triggered not because it is a crack, but exactly due to that.
 
Cracks often employ these analysis/checks because they don’t want their logics to be debugged and discovered, in this case the software developer will implement logics that will invalidate the crack. These logics awfully resemble what malware authors are doing and often, detection is triggered not because it is a crack, but exactly due to that.
I see. So as you said, the only way to see if it's malware or not is Wireshark and PE Studio, right? If I do get the results of the runs, I'll put them through ChatGPT and Claude. Are those AI models good at analyzing such results, or would they most likely be hogwash? Or should I share them with the forum?
 
I see. So as you said, the only way to see if it's malware or not is Wireshark and PE Studio, right? If I do get the results of the runs, I'll put them through ChatGPT and Claude. Are those AI models good at analyzing such results, or would they most likely be hogwash? Or should I share them with the forum?
These models will definitely help you, Claude specially.
 
Do I need any other tools, other than Wireshark and PE Studio?
If you are a developer and you wanna reverse engineer the malware, you may need a whole arsenal of tools, till you are able to reverse engineer (at least to an extent) the sample. However, this is not one sample, it’s a a large collection of programming code and 2-3 malware lines may be hidden in each one of these DLLs (unless they are signed). Reverse engineering that would be madness. Next month this time you will still be doing that.

Tip: you can ignore all DLLs that are signed (which is what Kaspersky probably did as well).

As you’ve also discovered that it uses VM detection logics (you shared this VT analysis), most likely the sample will just terminate on a virtual machine and traffic won’t be generated. Kaspersky has already analysed with some sophisticated tools they have inhouse and has determined it is not malware.

But you can still play.
 
If you are a developer and you wanna reverse engineer the malware, you may need a whole arsenal of tools, till you are able to reverse engineer (at least to an extent) the sample. However, this is not one sample, it’s a a large collection of programming code and 2-3 malware lines may be hidden in each one of these DLLs (unless they are signed). Reverse engineering that would be madness. Next month this time you will still be doing that.

Tip: you can ignore all DLLs that are signed (which is what Kaspersky probably did as well).

As you’ve also discovered that it uses VM detection logics (you shared this VT analysis), most likely the sample will just terminate on a virtual machine and traffic won’t be generated. Kaspersky has already analysed with some sophisticated tools they have inhouse and has determined it is not malware.

But you can still play.
To be fair, they did it in 2 minutes. I kid you not, their reasoning was this:

Hello,

This file is a pretty widespread crack for Acrobat Pro, our policies specifically restrict such files being regarded as malicious in case they actually don't contain anything malicious.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top