In the recent past, malware have become a serious cyber security threat which has not only targeted individuals and organizations but has also threatened the cyber space of countries around the world. Amongst malware variants, trojans designed for data espionage and backdoor creation dominates the threat landscape. This necessitates an in depth study of these malware with the scope of extracting static features like APIs, strings, IP Addresses, URLs, email addresses etc. by and large found in such malicious codes. Hence in this research paper, an endeavor has been made to establish a set of patterns, tagged as APIs and Malicious Strings persistently existent in these malware by articulating an analysis framework.
Targeted cyber-threats are topmost concern of organizations and technologies of today. Malwares having similar objectives bear common artifacts. Thus defining a detection mechanism based on such peculiar artifacts will not only help in detecting existing risks but also gives a considerable defense against unknown malicious attacks. About 903 known malware samples related to espionage were analyzed statically and a data set comprising related artifacts is established and also checked against the benign software. Weightage is given to each artifact on the difference of its existence in malicious and benign code and artifact’s relation to the expected targeted organization or technology thus catering for targeted attacks. Designed algorithm for detection of espionage attack has given 99.16 % of authentication and 99.33 % of precision. Real time alarm generation is also incorporated by API hooking using Detour library for latter detailed analysis of suspicious program or application by proposed algorithm.
Over the past few years, the enormous challenge ever faced by cyber space is to combat against cyber threats in the shape of malware attacks. Of these, Trojans stands out as the most common choice due to its deceptive and alluring properties. Most of the modern / sophisticated malwares are polymorphic in nature, thus signature / heuristics based techniques are becoming out of scope in outraging zero-day threats. By and large Trojan and its numerous variants have common static features which are always existent in such malwares. By exploiting this analogy, a set of features is determined by analyzing known samples which can be effectively plied for combating against zero-day attacks launched by means of unknown malicious codes.