We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

BAB0: A custom sample that bypassed cutting-edge APT attack detection tools

00:00

Formal Metadata

Title
BAB0: A custom sample that bypassed cutting-edge APT attack detection tools
Alternative Title
BAB0: Egy speciális minta, amely megkerülte a legmodernebb APT támadáserzékelo eszközöket
Title of Series
Part Number
28
Number of Parts
29
Author
License
CC Attribution 3.0 Germany:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
In this talk, we present BAB0, a custom sample that we developed for testing purposes and that bypassed 5 cutting-edge APT attack detection tools. We explain why BAB0 escaped detection both in the phase of infecting the victim and later during continuous communications with a remote C&C server. We show the tricks that we designed and implemented in BAB0 and try to make some demonstrations as well. We also elaborate on the problems of testing anti-APT products in general, and give some hints on new testing methodologies that are currently emerging within the AV test community.
Sample (statistics)System programmingSoftwareAdvanced Encryption StandardSource codeMalwareNetwork switching subsystemComplex (psychology)Exploit (computer security)Computer wormCodeEncryptionWorld Wide Web ConsortiumComputer virusProduct (business)Range (statistics)Statistical hypothesis testingStatistical hypothesis testingBit rateSineFunction (mathematics)TelecommunicationInteractive televisionExecution unitPersonal digital assistantUniform resource nameInformation securityServer (computing)BlogSummierbarkeitLemma (mathematics)VideoconferencingPresentation of a groupStatistical hypothesis testingBitSampling (statistics)Product (business)RadiusMultiplication signCore dumpLevel (video gaming)OracleNP-hardAdventure gameNetwork topologyEvent horizonInformationServer (computing)NeuroinformatikProxy serverMereologyQuantumComputer programmingParticle systemPhysical systemView (database)Range (statistics)Row (database)Statistical hypothesis testingRegular graphVotingNumberFeedbackMessage passingSet (mathematics)Speech synthesisVector spaceGoodness of fitSlide ruleResultantException handlingWebsiteSeries (mathematics)CodeTraffic reportingBlogReal numberComputer virus1 (number)Antivirus softwareFocus (optics)Integrated development environmentVulnerability (computing)Normal (geometry)Stress (mechanics)Different (Kate Ryan album)DivisorLimit (category theory)Computer configurationFunctional (mathematics)MalwareStaff (military)Digital video recorderElectronic mailing listRemote procedure callRight angleArithmetic meanLecture/Conference
Sample (statistics)Gastropod shellComputer iconWeb pageWeb 2.0Server (computing)NeuroinformatikDirectory serviceSampling (statistics)BitDependent and independent variablesTask (computing)Physical systemNetwork topologyClient (computing)EstimatorMathematicsComputer fileLetterpress printingDatabaseGame controllerStatistical hypothesis testingSource codeGoodness of fitContent (media)Computer animationLecture/Conference
Sample (statistics)Metropolitan area networkSpecial unitary groupMassArmFunctional (mathematics)Trojanisches Pferd <Informatik>Sampling (statistics)Gastropod shellView (database)Computer fileInformationModule (mathematics)Point (geometry)Directory serviceField (computer science)
Sample (statistics)Link (knot theory)Single-precision floating-point formatComputer-generated imageryWeb pageRobotComputer iconWireless Markup LanguageHeat transferServer (computing)MalwarePhysical lawPersonal area networkInterior (topology)InformationComputer iconPerspective (visual)Directory serviceMathematical analysisCodeLibrary (computing)Pointer (computer programming)Web pageWeb 2.0Heat transferComputer fileLink (knot theory)View (database)MereologySoftware frameworkContent (media)Right angleSoftwarePoint (geometry)Data transmissionMalwareSimilarity (geometry)Server (computing)Functional (mathematics)Product (business)Normal (geometry)AreaSingle-precision floating-point formatComputer programmingStatuteCASE <Informatik>Computer virusMultiplication signComputer clusterDirected graphFrame problemFluid staticsNoise (electronics)DistanceStatistical hypothesis testingMedical imagingVector spaceLecture/Conference
Sample (statistics)Statistical hypothesis testingTask (computing)Process (computing)Electronic mailing listReading (process)Computer networkClient (computing)Server (computing)Internet forumReal numberProxy serverGoogolRankingTelecommunicationHTTP cookieSteganographyUniform resource nameSummierbarkeitIdentity managementFlagMenu (computing)Physical lawInterior (topology)Metropolitan area networkEmulationSpecial unitary groupRaw image formatWave packetArmWide area networkLevel (video gaming)Lemma (mathematics)Maxima and minimaDiscrete element methodNewton's law of universal gravitationGrand Unified TheoryLimit (category theory)Software engineeringComputer-generated imageryWeb pageWebsiteKernel (computing)System identificationEuclidean vectorMathematical analysisNon-standard analysisLink (knot theory)Different (Kate Ryan album)MalwareComputer iconClient (computing)Product (business)Image registrationForcing (mathematics)Right angleMessage passingGraphical user interfaceIdentifiabilitySampling (statistics)QuicksortUniform resource locatorHeat transferArithmetic meanServer (computing)Local ring1 (number)NumberInternetworkingType theoryCore dumpDialectComputer fileDisk read-and-write headTelecommunicationHTTP cookieForm (programming)Social classPresentation of a groupProxy serverStandard deviationGoodness of fitProcess (computing)Metropolitan area networkNatural numberAutomationWebsiteInformationNormal (geometry)Order (biology)Internet forumYouTubeMultiplication signAdditionConnected spaceTracing (software)Statistical hypothesis testingComputer programmingValidity (statistics)Event horizonSoftwareFamilyComputer-assisted translationFunctional (mathematics)FeedbackView (database)Web pageSlide ruleWindowFlow separationField (computer science)RootkitVideo gameReal numberHoaxWeb 2.0Electronic mailing listBitQuery languageData storage deviceComputer animationLecture/Conference
ExplosionEvent horizonNuclear spaceFinitary relationSample (statistics)InformationPrototypePhysical systemExploit (computer security)Modul <Datentyp>Key (cryptography)CodeComputerMiniDiscRead-only memoryNP-hardPairwise comparisonRevision controlSimilarity (geometry)Scale (map)Formal languageDifferent (Kate Ryan album)Module (mathematics)MereologyMathematical analysisInformationString (computer science)Group actionTracing (software)Exploit (computer security)Statement (computer science)QuicksortPhysical systemSampling (statistics)Product (business)Event horizonModule (mathematics)Software developerNeuroinformatikPrototypeSimilarity (geometry)Cursor (computers)WhiteboardCASE <Informatik>Different (Kate Ryan album)Information securityMetric systemNumberPerimeterObject (grammar)FamilyGraph (mathematics)Order (biology)Forcing (mathematics)Traffic reportingPresentation of a groupWater vaporIntegrated development environmentVideo gameSoftwareView (database)Server (computing)Antivirus softwareArithmetic meanType theoryFormal languageRevision controlCategory of beingGoodness of fitPixelSemiconductor memoryComputer virusMalwareState of matterRemote procedure callReal numberNuclear spaceStack (abstract data type)Wave1 (number)Lecture/Conference
Moving averageExecution unitString (computer science)EncryptionSample (statistics)Limit (category theory)AreaInterior (topology)Wide area networkPointer (computer programming)Logical constantExclusive orAdditionAdvanced Encryption Standard3 (number)Annulus (mathematics)Value-added networkArmRaw image formatInfinityGamma functionModemWeightMassSpecial unitary groupBuffer overflowCursor (computers)Block (periodic table)Convex hullSummierbarkeitLevel (video gaming)CoroutineAmsterdam Ordnance DatumSoftware engineeringMaxima and minimaMetropolitan area networkUniform resource nameError correction modelSineGrand Unified TheoryBinary fileoutputNewton's law of universal gravitationFunction (mathematics)Parameter (computer programming)Set (mathematics)Server (computing)ImplementationComputer networkTelecommunicationClient (computing)HTTP cookieComa BerenicesStandard deviationCache (computing)Control flowCodeMessage passingComputer fileSlide ruleStatistical hypothesis testingPerspective (visual)NumberString (computer science)Peg solitaireTable (information)Software developerSimilarity (geometry)Loop (music)Electronic mailing listQuicksortWechselseitige InformationMereologyDisk read-and-write headSampling (statistics)Revision controlStaff (military)Web 2.0Different (Kate Ryan album)Communications protocolVotingNuclear spaceComputer programmingLocal ringOperator (mathematics)InformationPairwise comparisonOpen setGene clusterLoginVector spaceTelecommunicationMultiplication signSpring (hydrology)EncryptionIdentifiabilityRandom number generationElectronic signatureLibrary (computing)CoroutinePoint (geometry)Traffic reportingSpeech synthesisBitProduct (business)Data transmissionGroup actionImplementationProcess (computing)Basis <Mathematik>Proof theoryBlogBuffer overflowCASE <Informatik>40 (number)Data structureBlock (periodic table)DialectMathematical analysisDescriptive statisticsGradientPauli exclusion principleMetric systemCompilerExecution unitGodFunctional (mathematics)Crash (computing)Connected spaceAdditionLinker (computing)Integrated development environmentHTTP cookieCryptographyBinary codeVirtualizationSoftware bugNormal (geometry)Advanced Encryption StandardWordSystem callFunction (mathematics)Complete metric spaceAuthorizationExclusive orStandard deviationRoundness (object)Error messageLecture/Conference
Repository (publishing)CollaborationismExpert systemSample (statistics)Computer hardwareKey (cryptography)Public key certificateOperations researchSystem programmingElectronic signatureStandard deviationFormal verificationSoftwarePhysical systemDevice driverKernel (computing)ChainAndroid (robot)Java appletObject (grammar)Hand fanDifferent (Kate Ryan album)StatisticsView (database)Graph (mathematics)DatabaseParsingAttribute grammarTable (information)Open sourceArchitectureType theoryModul <Datentyp>Process (computing)Regular graphQuery languageInterface (computing)World Wide Web ConsortiumDistribution (mathematics)MalwareMobile appLibrary catalogComputer-assisted translationMaizeServer (computing)Total S.A.Newton's law of universal gravitationEmulationSign (mathematics)SummierbarkeitInformationImage registrationAntivirus softwareInternetworkingKey (cryptography)Physical systemSampling (statistics)Type theoryCartesian coordinate systemCodeWeb applicationSoftware developerServer (computing)Computer virusCodeDatabaseNumberComputer fileObject (grammar)Multiplication signFunctional (mathematics)Data storage deviceHash functionElectronic signatureResultantDifferent (Kate Ryan album)Power (physics)PrototypeDigitizingDevice driverTotal S.A.Public-key cryptographyJava appletMalwareAndroid (robot)Equaliser (mathematics)WindowComputer hardwareBinary codeSimilarity (geometry)Sign (mathematics)Public key certificateTable (information)Repository (publishing)Source codeProduct (business)TelecommunicationIntegrated development environmentView (database)Graph (mathematics)Web crawlerNeuroinformatikPort scannerFeedbackArithmetic meanInterface (computing)CASE <Informatik>Presentation of a groupTangentSemiconductor memoryNatural languagePhysicsCausalityProcess (computing)Local ringStatistical hypothesis testingNetwork topologyEvent horizonWebsiteCommunications protocolSummierbarkeitRow (database)Right angleLecture/Conference
Transcript: English(auto-generated)