1
00:00:00,090 --> 00:00:00,960
In this lesson,

2
00:00:00,960 --> 00:00:02,700
I want to perform a quick demonstration to

3
00:00:02,700 --> 00:00:04,140
show you how easy it is to create

4
00:00:04,140 --> 00:00:06,870
and use a virus and remote access Trojan.

5
00:00:06,870 --> 00:00:08,670
Now, before we begin, it's important to note

6
00:00:08,670 --> 00:00:10,770
that I'm using an older, legacy style machine

7
00:00:10,770 --> 00:00:11,970
for this demonstration

8
00:00:11,970 --> 00:00:14,580
because these are known vulnerable Windows 7 machines

9
00:00:14,580 --> 00:00:16,830
that I'm using inside of my lab environment.

10
00:00:16,830 --> 00:00:18,630
Now, this is a great operating system to use

11
00:00:18,630 --> 00:00:20,400
for these types of security demonstrations,

12
00:00:20,400 --> 00:00:21,720
because they are vulnerable

13
00:00:21,720 --> 00:00:24,150
and there are no longer any new security patches

14
00:00:24,150 --> 00:00:26,580
for Windows 7 systems in existence.

15
00:00:26,580 --> 00:00:28,470
So if you're trying to replicate this demonstration

16
00:00:28,470 --> 00:00:31,740
on a more modern workstation like Windows 11 or Windows 10,

17
00:00:31,740 --> 00:00:33,450
it will usually be detected and blocked

18
00:00:33,450 --> 00:00:36,540
by your modern antivirus software like Windows Defender.

19
00:00:36,540 --> 00:00:38,490
But there are newer tools that are being developed

20
00:00:38,490 --> 00:00:40,920
by threat actors, attackers, and penetration testers

21
00:00:40,920 --> 00:00:42,810
all the time that you can use.

22
00:00:42,810 --> 00:00:44,130
Now, I've had many students ask

23
00:00:44,130 --> 00:00:46,860
where they can download a tool like JPS Virus Maker

24
00:00:46,860 --> 00:00:48,480
that I'm going to be using in this demo

25
00:00:48,480 --> 00:00:50,310
and you can find these things online.

26
00:00:50,310 --> 00:00:51,870
Now, because I did not create this tool

27
00:00:51,870 --> 00:00:53,490
and I don't own the copyright to it,

28
00:00:53,490 --> 00:00:55,920
I am not able to provide you a direct download link

29
00:00:55,920 --> 00:00:57,870
for this tool or tell you where you

30
00:00:57,870 --> 00:00:59,430
can actually go and download it.

31
00:00:59,430 --> 00:01:01,890
Making a virus is not considered a testable item

32
00:01:01,890 --> 00:01:03,630
for your exams, but I wanted to provide

33
00:01:03,630 --> 00:01:05,400
this quick demonstration so you can see

34
00:01:05,400 --> 00:01:07,620
what kind of things a virus and a Trojan can do

35
00:01:07,620 --> 00:01:10,140
once they've compromised your targeted system.

36
00:01:10,140 --> 00:01:11,190
Now, if you move into the world

37
00:01:11,190 --> 00:01:13,110
of penetration testing later on in your career,

38
00:01:13,110 --> 00:01:15,000
you'll learn all about the different tools that we use

39
00:01:15,000 --> 00:01:17,190
in modern networks to be able to create viruses

40
00:01:17,190 --> 00:01:18,390
and Trojans to be able to break

41
00:01:18,390 --> 00:01:19,590
into corporate networks as part

42
00:01:19,590 --> 00:01:22,650
of your penetration testing assessments and engagements.

43
00:01:22,650 --> 00:01:25,410
Alright, let's jump into the demonstration.

44
00:01:25,410 --> 00:01:27,330
So I have two machines set up here.

45
00:01:27,330 --> 00:01:29,310
I have one on the left, which will be my attacker

46
00:01:29,310 --> 00:01:32,220
and one on the right, which will be my victim.

47
00:01:32,220 --> 00:01:33,390
On the attacker's machine,

48
00:01:33,390 --> 00:01:37,860
I'm running a program called Virus Maker 3.0, or JPS.

49
00:01:37,860 --> 00:01:40,320
Here is basically a point and click options

50
00:01:40,320 --> 00:01:41,790
of all the things that I can do

51
00:01:41,790 --> 00:01:43,440
to that machine on the right.

52
00:01:43,440 --> 00:01:44,730
For our example, I'm going to do one

53
00:01:44,730 --> 00:01:47,610
that's easy to see, it's called Crazy Mouse.

54
00:01:47,610 --> 00:01:49,140
So I'll go ahead and click that

55
00:01:49,140 --> 00:01:50,790
and then I'm going to select what do I want it

56
00:01:50,790 --> 00:01:52,560
to be called after installation.

57
00:01:52,560 --> 00:01:54,810
We'll go ahead and call it the service host.

58
00:01:54,810 --> 00:01:56,820
And what do we want the server name to be called?

59
00:01:56,820 --> 00:01:58,440
The file name, and I'm going to go ahead

60
00:01:58,440 --> 00:02:00,780
and call it Explorer.exe.

61
00:02:00,780 --> 00:02:02,610
You could really choose whatever you want.

62
00:02:02,610 --> 00:02:05,310
It just depends on how sneaky you're trying to be.

63
00:02:05,310 --> 00:02:06,630
Now, the next thing I'm going to do is

64
00:02:06,630 --> 00:02:08,133
I'm going to create that virus.

65
00:02:09,030 --> 00:02:10,680
At this point that has been created

66
00:02:10,680 --> 00:02:12,960
and saved to my downloads folder.

67
00:02:12,960 --> 00:02:14,790
Now at this point, I need my victim to be able

68
00:02:14,790 --> 00:02:17,250
to download this virus, and there's lots of ways

69
00:02:17,250 --> 00:02:19,950
to do that based on your social engineering,

70
00:02:19,950 --> 00:02:22,590
tying this virus into another program,

71
00:02:22,590 --> 00:02:24,630
using a spear phishing campaign,

72
00:02:24,630 --> 00:02:27,720
putting it as a rogue download, all sorts of things.

73
00:02:27,720 --> 00:02:29,070
For this particular example though,

74
00:02:29,070 --> 00:02:30,660
I'm just going to show you the effect

75
00:02:30,660 --> 00:02:32,220
if the person was able to download it

76
00:02:32,220 --> 00:02:33,720
and if they ran it.

77
00:02:33,720 --> 00:02:35,700
So at this point the user's been tricked,

78
00:02:35,700 --> 00:02:37,830
they've downloaded the file and now they run it

79
00:02:37,830 --> 00:02:40,440
because they think it's a game or whatever else it is.

80
00:02:40,440 --> 00:02:42,240
In this case, they think it's a picture.

81
00:02:42,240 --> 00:02:44,943
If we go ahead and run that, see what happens.

82
00:02:46,200 --> 00:02:47,940
And there you can see the mouse just starts

83
00:02:47,940 --> 00:02:49,770
going jumping all over the screen

84
00:02:49,770 --> 00:02:51,450
so that if I wanted to try to open something

85
00:02:51,450 --> 00:02:53,850
like the trash can I can't because every time I click on it,

86
00:02:53,850 --> 00:02:55,800
it jumps away someplace else.

87
00:02:55,800 --> 00:02:58,020
That's the idea of this very simple virus.

88
00:02:58,020 --> 00:02:59,820
It's just a nuisance, it's trying to cause

89
00:02:59,820 --> 00:03:00,770
a problem for them.

90
00:03:01,800 --> 00:03:03,330
Now, let me show you an example

91
00:03:03,330 --> 00:03:06,930
of what a remote access Trojan or RAT looks like.

92
00:03:06,930 --> 00:03:08,850
Now, on the left is my attacking machine

93
00:03:08,850 --> 00:03:11,580
and on the right is my victim machine.

94
00:03:11,580 --> 00:03:14,820
So I'm using a program called ProRat.

95
00:03:14,820 --> 00:03:18,390
So the first thing I want to do is create a ProRat server.

96
00:03:18,390 --> 00:03:20,190
I'm going to click on General Settings

97
00:03:20,190 --> 00:03:21,300
and from here you can see the port

98
00:03:21,300 --> 00:03:23,610
it's going to operate on: 5110,

99
00:03:23,610 --> 00:03:25,740
which I can change to anything I want.

100
00:03:25,740 --> 00:03:28,710
The server password in this case, 12345.

101
00:03:28,710 --> 00:03:30,360
Again, not very secure,

102
00:03:30,360 --> 00:03:32,700
but for our lab purposes it's just fine.

103
00:03:32,700 --> 00:03:35,070
And then the victim's name if we have it.

104
00:03:35,070 --> 00:03:37,680
From here we can give them error messages,

105
00:03:37,680 --> 00:03:39,810
we can melt the server on install

106
00:03:39,810 --> 00:03:41,310
which means once the Pro Rat has

107
00:03:41,310 --> 00:03:43,080
been installed on the victim computer,

108
00:03:43,080 --> 00:03:46,170
it will delete itself while still maintaining a connection.

109
00:03:46,170 --> 00:03:49,140
We can kill the antivirus and the firewall on start,

110
00:03:49,140 --> 00:03:50,850
we can disable Security Center

111
00:03:50,850 --> 00:03:52,980
and all sorts of other things like that.

112
00:03:52,980 --> 00:03:54,600
I'm going to go ahead and give a fake error message

113
00:03:54,600 --> 00:03:57,450
here saying "You have been hacked."

114
00:03:57,450 --> 00:03:59,070
Now, normally you wouldn't want to send a message

115
00:03:59,070 --> 00:04:01,110
to your user showing that they've been hacked,

116
00:04:01,110 --> 00:04:03,660
but I just want to show it to you for demonstration purposes.

117
00:04:03,660 --> 00:04:05,460
Maybe you're doing this as a ransomware

118
00:04:05,460 --> 00:04:06,690
and you've encrypted their files.

119
00:04:06,690 --> 00:04:08,587
This is a way to send them a message saying

120
00:04:08,587 --> 00:04:11,040
"You need to pay me if you want access to it."

121
00:04:11,040 --> 00:04:12,780
And from there we'll just go down

122
00:04:12,780 --> 00:04:15,420
and we can go ahead and hit Create Server.

123
00:04:15,420 --> 00:04:17,920
From there, the server is going to be created for us.

124
00:04:18,899 --> 00:04:19,899
Go ahead and hit OK.

125
00:04:20,970 --> 00:04:22,650
So if we want to be a little trickier,

126
00:04:22,650 --> 00:04:24,660
we're going to go ahead and bind it with a file.

127
00:04:24,660 --> 00:04:26,340
So we're going to select a picture,

128
00:04:26,340 --> 00:04:27,750
in this case, the desert.

129
00:04:27,750 --> 00:04:29,520
Go ahead and hit Open on that

130
00:04:29,520 --> 00:04:32,310
and then we're going to give it another server extension here.

131
00:04:32,310 --> 00:04:37,310
We want to call it EXE, SCR, COM, PIF or BAT.

132
00:04:37,350 --> 00:04:40,110
EXE will be just fine and for the icon,

133
00:04:40,110 --> 00:04:41,400
what do we want this to look like?

134
00:04:41,400 --> 00:04:43,380
Well, we want it to look like a photo,

135
00:04:43,380 --> 00:04:45,530
so we're going to go ahead and make it a JPEG.

136
00:04:46,620 --> 00:04:49,443
And then we can go ahead and hit Create the Server.

137
00:04:52,200 --> 00:04:53,820
And this is going to be in our current directory,

138
00:04:53,820 --> 00:04:56,220
so if I look back in my current directory

139
00:04:56,220 --> 00:05:00,540
I now have the binded server with a JPEG icon.

140
00:05:00,540 --> 00:05:01,710
And from here we can go ahead

141
00:05:01,710 --> 00:05:04,170
and rename it and let's call it "Desert".

142
00:05:04,170 --> 00:05:07,110
So now they think they're getting a photo of the desert.

143
00:05:07,110 --> 00:05:09,150
At this point, again, we would use some form

144
00:05:09,150 --> 00:05:11,790
of trickery or social engineering to get it to them

145
00:05:11,790 --> 00:05:14,850
and once we do, it'll be on their desktop.

146
00:05:14,850 --> 00:05:16,560
So at this point I've tricked the user

147
00:05:16,560 --> 00:05:18,180
and they now have the file.

148
00:05:18,180 --> 00:05:20,040
They're going to go ahead and open that file,

149
00:05:20,040 --> 00:05:21,633
and when they run that file,

150
00:05:22,470 --> 00:05:25,200
you're going to see the error message that we told it to have.

151
00:05:25,200 --> 00:05:27,570
There's the picture and "You have been hacked."

152
00:05:27,570 --> 00:05:29,670
Uh-oh, now what's going on?

153
00:05:29,670 --> 00:05:31,740
Let's go ahead onto our target machine

154
00:05:31,740 --> 00:05:34,560
and connect to that server that's now been installed.

155
00:05:34,560 --> 00:05:37,500
Again, we're going to use our password 12345,

156
00:05:37,500 --> 00:05:39,960
and at this point we now have access to that machine.

157
00:05:39,960 --> 00:05:42,330
We can find out information about it.

158
00:05:42,330 --> 00:05:45,090
In this case, if we go ahead and get the system information,

159
00:05:45,090 --> 00:05:47,910
I know now the computer name is Bob Sales.

160
00:05:47,910 --> 00:05:49,710
I know what kind of machine it is,

161
00:05:49,710 --> 00:05:51,815
it's using English for its language,

162
00:05:51,815 --> 00:05:53,610
System32 is its path,

163
00:05:53,610 --> 00:05:55,380
I find out what kind of users it has,

164
00:05:55,380 --> 00:05:57,750
I find out the date and time of the machine,

165
00:05:57,750 --> 00:05:59,340
all of that information.

166
00:05:59,340 --> 00:06:01,110
And if I close this on the right,

167
00:06:01,110 --> 00:06:02,490
that'll move out of the way.

168
00:06:02,490 --> 00:06:04,470
We can get all that information here

169
00:06:04,470 --> 00:06:07,710
from our attacking machine about our victim machine.

170
00:06:07,710 --> 00:06:10,650
We can also look at the last 25 websites they visited

171
00:06:10,650 --> 00:06:12,300
and maybe that would be something that would be helpful

172
00:06:12,300 --> 00:06:13,740
for us to be able to attack.

173
00:06:13,740 --> 00:06:16,470
We can take screenshots and we can actually open it

174
00:06:16,470 --> 00:06:17,700
and see what we're going to see.

175
00:06:17,700 --> 00:06:20,880
So if I do a screenshot, I see what's on their screen.

176
00:06:20,880 --> 00:06:25,050
So if they're on a website like Google here

177
00:06:25,050 --> 00:06:25,912
which is not going to connect

178
00:06:25,912 --> 00:06:27,870
'cause I'm in a live environment here

179
00:06:27,870 --> 00:06:30,180
that's disconnected from the machine,

180
00:06:30,180 --> 00:06:32,520
I'll go ahead and hit Snapshot and now I can see that.

181
00:06:32,520 --> 00:06:35,010
If they had a webcam, I could view their webcam.

182
00:06:35,010 --> 00:06:37,440
Again, I have lots of access to do whatever it is

183
00:06:37,440 --> 00:06:39,390
we want to do on this machine.

184
00:06:39,390 --> 00:06:41,400
I can send them messages if I want,

185
00:06:41,400 --> 00:06:44,403
so I can do a message and say Test.

186
00:06:45,480 --> 00:06:47,130
And it'll say, "I don't work for you anymore",

187
00:06:47,130 --> 00:06:49,620
so we're going to go ahead and send that over there.

188
00:06:49,620 --> 00:06:50,453
And there it is.

189
00:06:50,453 --> 00:06:52,380
"I'm sorry, I don't work for you anymore."

190
00:06:52,380 --> 00:06:55,410
And so you can see the power of a remote access tool,

191
00:06:55,410 --> 00:06:58,470
and so this allows me to do all sorts of different stuff.

192
00:06:58,470 --> 00:07:00,480
Again, I can take their files,

193
00:07:00,480 --> 00:07:02,400
I can mess with their registry,

194
00:07:02,400 --> 00:07:04,260
I can go through and look at all their files,

195
00:07:04,260 --> 00:07:06,630
I can FTP over and grab their files,

196
00:07:06,630 --> 00:07:08,070
I can chat over to them.

197
00:07:08,070 --> 00:07:09,210
I can do some funny stuff.

198
00:07:09,210 --> 00:07:10,440
Maybe it's my friend and I'm just trying

199
00:07:10,440 --> 00:07:12,870
to show them that I have access to their machine.

200
00:07:12,870 --> 00:07:15,240
For instance, I can hide their desktop icons,

201
00:07:15,240 --> 00:07:17,940
and now you should be able to see that that is gone.

202
00:07:17,940 --> 00:07:20,190
And I can show their icons and they're back.

203
00:07:20,190 --> 00:07:23,550
I can make the mouse go crazy and then I can fix it.

204
00:07:23,550 --> 00:07:26,910
I can flip their screen upside down and then I can fix it.

205
00:07:26,910 --> 00:07:29,460
So you can do all sorts of different things

206
00:07:29,460 --> 00:07:31,893
on this machine and take control and do whatever it is

207
00:07:31,893 --> 00:07:35,910
that we want because we have that remote access to them.

208
00:07:35,910 --> 00:07:37,920
I hope you found this demonstration insightful

209
00:07:37,920 --> 00:07:40,080
as you started to see what kind of effects a virus

210
00:07:40,080 --> 00:07:43,263
or a remote access Trojan can have on a victimized system.

