Malware Zoo Teacher Guide The Malware Zoo
Teacher Facilitation Guide
Lesson 1 of 5
Time: 50-60 Minutes
Instructional Goal
Students will differentiate between viruses and worms by investigating their replication methods and analyzing the historical impact of the Morris Worm.
Essential Question
Can a computer get the flu? How do digital infections spread without human help?
Key Vocabulary
Malware: Malicious software.
Virus: Needs a host file/human.
Worm: Self-replicating via network.
Morris Worm: First major internet worm.
1
The Hook (5-10 mins)
Ask: "How do humans get sick?" List answers (contact, sneezing, shared food). Then ask: "Can a computer catch a cold?" Transition to the idea that just like biological viruses, computer viruses need a "host" to spread.
2
The Malware Zoo (15 mins)
Use the slide deck to define Malware as the umbrella term. Focus on the core difference: Viruses require human action (opening an attachment, clicking a link), while Worms exploit network vulnerabilities to jump from machine to machine automatically.
3
The Morris Worm Case Study (20 mins)
Distribute the "Malware Lab Notes" worksheet. Students read the brief summary of the 1988 Morris Worm. Discuss: Why was it so dangerous? (It wasn't meant to be destructive, but a coding error made it crash the entire internet of 1988).
4
The Classification Challenge (10 mins)
Students complete the "Classification Table" on their worksheet, categorizing different scenarios as either Virus or Worm behaviors.
Differentiation & Support
Scaffolding:
Provide a Venn diagram graphic organizer for students who struggle with the Virus vs. Worm distinction.
Extension:
Ask students to research the "I Love You" worm and compare its spread to the Morris Worm.
Answer Key: Malware Lab Notes
Part 1: The Definitions
Virus: Malicious code that attaches itself to a host file and requires human action (clicking, opening) to spread.
Worm: Standalone malicious software that can replicate and spread across networks automatically without human intervention.
Part 2: The Morris Worm Impact
Why did it spread so fast? It exploited bugs in several network programs and tried common passwords to break into systems.
Was it intended to destroy? No, Robert Morris claimed it was to measure the size of the internet, but a bug caused it to re-infect machines until they crashed.
Part 3: Virus vs. Worm Scenario Sort
Scenario Type A program waits for you to click "Open-Free-Game.exe" to start infecting your files. Virus A malicious file scans the school Wi-Fi and automatically jumps into every connected laptop. Worm A hidden script inside an Excel spreadsheet runs when the user enables macros. Virus A program exploits a security hole in the operating system to send copies of itself to other servers. Worm
Malware Lab Notes Worksheet Malware Lab Notes
Digital Forensics Unit | Lesson 01
Agent Name:
Date:
Phase 1
Classifying the Threats
During the class presentation, record the key differences between these two common types of malware.
Computer Virus
Working Definition:
Key Characteristic (The "Host"):
Computer Worm
Working Definition:
Key Characteristic (Replication):
01101101 01101111 01110010 01110010 01101001 01110011 00001010 01110111 01101111 01110010 01101101
Case Study: The 1988 Morris Worm
In November 1988, a graduate student named Robert Morris released a program from a computer at MIT. It wasn't designed to delete files or steal data. Instead, it was meant to "crawl" the internet to count how many computers were connected.
However, the worm had a fatal flaw: it was too aggressive. It would re-infect computers that were already infected, eventually using up all the computer's memory until it crashed. Thousands of computers—about 10% of the entire internet at the time—went offline.
The Impact
Cost: Millions in repair time.
First felony conviction under the Computer Fraud and Abuse Act.
Led to the creation of CERT (Computer Emergency Response Team).
1. Based on the case study, why is the Morris program classified as a Worm rather than a Virus?
2. Robert Morris said he didn't mean to cause damage. Why should he still be held responsible for the crash?
Phase 2
The Sorting Room
Read each scenario below. Identify if it describes a Virus or a Worm and explain your reasoning by looking for "The Trigger."
Scenario A: You download a "Free Wallpaper" app. When you double-click the file to install it, a script secretly starts deleting your photos.
Virus
Worm
Scenario B: A malicious program finds a weakness in a school's server. Over the weekend, it copies itself onto every student's tablet connected to the Wi-Fi while they are sleeping.
Virus
Worm
Scenario C: You receive an email from a "friend" with a PDF attachment named "CheckThisOut." You open the PDF, and suddenly your email starts sending the same file to everyone in your contact list.
Virus
Worm
Agent Reflection
What is ONE thing you can do on your own computer to prevent a Virus from spreading?
Malware Zoo Slides 01010111 01001111 01010010 01001101 01010011 00100000 01000001 01001110 01000100 00100000 01010110 01001001 01010010 01010101 01010011 01000101 01010011 01010111 01001111 01010010 01001101 01010011 00100000 01000001 01001110 01000100 00100000 01010110 01001001 01010010 01010101 01010011 01000101 01010011
The Malware Zoo
Lesson 01: Viruses & Worms
Detect Analyze Defend
Can a Computer Get "Sick"?
"Think about the last time you had a cold. How did you catch it?"
Shared surfaces?
Being near someone?
Cyber Reality Check:
In the digital world, "germs" are called Malware.
Malicious + Software = Malware
The Computer Virus
Rule #1: It needs a Host
Just like a biological virus needs a living cell, a computer virus attaches itself to a legitimate file or program (like a game or a PDF).
Rule #2: It needs Action
It cannot spread on its own. It waits for YOU to:
Click a Link Open an Email Download a File
No Click = No Virus
The Computer Worm
1
Self-Replicating
It makes copies of itself without any human help.
2
Network Traveler
It uses "backdoors" or security holes to jump from one computer to another over Wi-Fi or the Internet.
"While a virus is like a passenger on a plane, a worm is the pilot of its own jet."
The Worm that Broke the Net
Robert Morris
Graduate Student, 1988
Mission: Count the Web
Morris wrote a program to count how many computers were on the internet. But his code had a bug.
The Result:
The worm infected computers over and over until they were so full of "clones" that they crashed.
Total Damage: ~6,000 computers (10% of the entire internet in 1988!)
Open your Lab Notes to "Phase 2" to analyze the case...
Trojans Ransomware Teacher Guide Trojans and Ransomware
Teacher Facilitation Guide
Lesson 2 of 5
Time: 50-60 Minutes
Instructional Goal
Students will understand how Trojan horses use deception to bypass security and how Ransomware exploits that access to extort victims. They will also explore the ethical complexities of paying digital ransoms.
Essential Question
If a piece of software looks useful, can you trust it? Should we pay criminals to get our data back?
Key Vocabulary
Trojan Horse: Malware disguised as useful software.
Ransomware: Encrypts data and demands payment.
Encryption: Scrambling data so it's unreadable.
Ethics: Moral principles that govern behavior.
1
The Hook: The Legend (5-10 mins)
Briefly recount the story of the wooden horse of Troy. Ask: "Why did the Trojans let the horse in?" (They thought it was a gift). Explain that in computing, Trojans use the same trick: looking like a "gift" (free game, cool tool) to get past your defenses.
2
Trojans vs. Ransomware (15 mins)
Use the slides to explain that a Trojan is the delivery method , while Ransomware is often the payload . Define Ransomware: it doesn't just steal data; it locks it up using encryption and asks for money (usually Bitcoin) to unlock it.
3
The Ethical Ransom Debate (20 mins)
Distribute the "To Pay or Not To Pay" worksheet. Present three scenarios: a family's photos, a local hospital's records, and a major city's infrastructure. Students work in groups to decide if the ransom should be paid and what the consequences of paying (or not) might be.
4
Discussion & Debrief (10 mins)
Poll the class: Should we ever pay? Introduce the FBI's stance (don't pay, it funds more crime) vs. the reality of high-stakes situations like hospitals.
Differentiation & Support
Visual Learners:
Draw a diagram on the board showing a "Useful App" box with a "Malicious Worm" hidden inside to visualize the Trojan concept.
Extension:
Have students research the "WannaCry" ransomware attack and find out how it was eventually stopped by a "kill switch."
Discussion Guide: Ethical Ransoms
Key Arguments: WHY PAY?
Speed: Paying is often the fastest way to get data back and restore services (critical for hospitals).
Certainty: If backups are missing or failed, paying might be the only option to save years of work or memories.
Ransomware Ethics Worksheet To Pay or Not To Pay?
The Ethics of Ransomware
Student:
Period:
The Ransomware Trap
Ransomware doesn't just steal your data—it uses encryption to scramble it like a secret code. Without the "key" from the attacker, you can never read your files again. Usually, the attacker demands payment in Bitcoin (digital money that is hard to trace).
Case Study Scenarios
Review the three scenarios below. For each, decide if you would pay the ransom and explain why.
Scenario A: The Family Photos
Ransom: $300
"Your family's computer is infected. All 10 years of your childhood photos and videos are locked. You have no backup. The ransom is $300."
PAY IT
REFUSE
Scenario B: The City Hospital
Ransom: $500,000
"A hospital's patient records are encrypted. Doctors can't see who needs surgery or what medicine people are allergic to. The hospital can't function."
PAY IT
REFUSE
Scenario C: The Video Game Studio
Ransom: $2,000,000
"A game studio's new top-secret game code is stolen and locked. If they don't pay, the attackers will leak the secret ending online."
PAY IT
REFUSE
Ethical Reflection
If everyone REFUSED to pay, what would happen to the ransomware industry?
If you DO pay, what is the biggest risk you are taking? Trojans Ransomware Slides The Gift &
The Lock
Trojans & Ransomware
The Ancient Trick
The Story:
The Greeks built a giant wooden horse as a "gift." The Trojans brought it inside their city walls. At night, Greek soldiers crawled out and captured the city.
The Malware:
A Trojan Horse is malicious software that looks like something useful (a free game, a calculator, a funny video) so you will let it "inside" your computer.
How a Trojan Attacks
Step 1: Bait
User downloads a "Useful" app.
Step 2: Install
User runs the app. It works, but it also installs a "payload."
Step 3: Exploit
The malware now has a "backdoor" into your system.
Ransomware: Digital Kidnapping
Encryption
The malware uses a complex code to scramble all your files. Without the "key," they are just gibberish.
The Demand
A message pops up on your screen. "Pay $500 in Bitcoin within 48 hours or your files will be deleted forever."
YOUR FILES ARE ENCRYPTED
Many hospitals, cities, and schools have been hit by ransomware, forcing them to shut down services.
Time Remaining: 47:59:58
Should we ever pay the ransom?
"Paying might get your data back, but it also pays for the attacker's next crime. What would YOU do?"
Team PAY IT
Team NO WAY
Open your "To Pay or Not To Pay" worksheet
Phishing Lab Teacher Guide Phishing Lab
Teacher Facilitation Guide
Lesson 3 of 5
Time: 50-60 Minutes
Instructional Goal
Students will identify the common markers of phishing emails and learn technical verification skills, specifically URL analysis through the "hover" method.
Essential Question
How do we know if an email is really from who it says it's from?
Key Vocabulary
Phishing: Fraudulent emails to steal info.
Sense of Urgency: Making you act fast.
Display Name: The name you see (faked).
URL: The actual web address.
1
The Hook: "You Won!" (5-10 mins)
Tell the class: "I just got an email saying I won a $1,000 Amazon gift card! All I have to do is log in to my bank to 'verify' my identity. Should I do it?" Discuss why this sounds suspicious (too good to be true, weird request).
2
The SLAM Method (15 mins)
Introduce the SLAM checklist for emails:
• Sender (Check the actual email address)
• Links (Hover to see the destination)
• Attachments (Are they unexpected?)
• Message (Spelling errors, urgent tone?)
3
Spot the Fake Lab (25 mins)
Students use the "Phish Finder" worksheet to analyze 4 email examples. They must circle the "red flags" and decide if the email is a Phish or a Friend.
4
URL Anatomy Quiz (5 mins)
Show two URLs (e.g., google.security.com vs. security.google.com). Explain that the *end* of the domain (google.com) is the owner. Students practice identifying the real owner.
Technical Tip
Remind students that on tablets/mobile, you "hover" by long-pressing a link to see the preview URL. Never just tap!
Answer Key: Phish Finder Lab
Email 1: Netflix Payment Issue
Verdict: PHISH. Red flags: Sender is "support@netflix-security.xyz " (not netflix.com), greeting is generic "Dear Customer," sense of urgency ("24 hours or account closed").
Email 2: School Newsletter
Verdict: FRIEND. Sender is "principal@school.edu ", link hovers to "school.edu/newsletter", tone is informational, no urgent demand for personal info.
Email 3: Gaming Reward
Verdict: PHISH. Red flags: Too good to be true (Free 10,000 Robux), link hovers to "get-free-coins.net", spelling errors ("congradulations").
URL Identification Challenge
1. -> FAKE (Real owner is support-update.com)
Phish Finder Lab Worksheet Phish Finder Lab
Threat Detection Exercise
REF_ID: CYBER-L3-P1
SENSITIVITY: HIGH
S
Sender
Check the actual email address, not just the name.
L
Links
Hover over any link to see where it REALLY goes.
A
Attachments
Unexpected file? Don't open it. It's a Trojan trap.
M
Message
Urgent tone? Spelling errors? Generic greeting?
N
Netflix Support account-security@verify-now.net
2:14 PM
Subject: ACTION REQUIRED: Your account is suspended
Dear Customer,
We were unable to process your last payment. To keep your movies streaming, you must update your credit card info within 24 hours or we will delete your profile forever.
Update Payment Info
Hovering over the button reveals: http://bit.ly/login-scam-392
Verdict:
PHISH
FRIEND
Explain 2 red flags here...
S
School Admin notifications@lincoln-ms.edu
8:05 AM
Subject: Lunch Menu Update for October
Hello Students and Parents,
The new lunch menu for the month of October is now available on our school website. We have added Taco Tuesday back by popular demand! You can view the full schedule below.
View October Menu PDF
Hovering over the link reveals: https://www.lincoln-ms.edu/lunch/october.pdf
Verdict:
PHISH
FRIEND
Why is this safe/unsafe?
Part 2: URL Anatomy
To find the Real Owner of a website, look at the last two parts of the domain name (just before the first single slash /).
https://accounts.google.com/login
The Real Owner is GOOGLE.COM
Identify the REAL OWNER of these suspicious URLs:
microsoft.security-update.net/fix
Who owns this site?
login.roblox.com.scam-site.biz
Who owns this site?
amazon.shipping-details.com/package
Who owns this site?
The Golden Rule
"If you are ever unsure, NEVER click the link in the email. Instead, go directly to the official website (like typing 'netflix.com' yourself) to check for messages."
Phishing Lab Slides Don't Take
the Bait
Lesson 03: Phishing Lab
What is Phishing?
Attackers use Social Engineering to trick you into giving up your most valuable digital secrets.
The Goal:
> Usernames & Passwords
> Credit Card Numbers
> Identity Information
Fake Email
SCAM!
The SLAM Method
Your 4-Step Checklist for EVERY Email
S
Sender
Is the email address official? Check for small typos!
L
Links
Hover before you click. Does the real URL match?
A
Attach
Were you expecting this file? Is it a .exe or .zip?
M
Message
Generic greeting? "Urgent" threat? Bad spelling?
Master the Hover
What you see:
Click here to reset your Google Password
Wait! Hover your mouse first...
What the computer sees:
http://google-security-update.badguy.net/scam
The real owner is: badguy.net
When in doubt,
Throw it out.
Never click the link in the email. Go directly to the official app or website yourself.
Time for the Phish Finder Lab!
Social Engineering Teacher Guide Social Engineering Tactics
Teacher Facilitation Guide
Lesson 4 of 5
Time: 50-60 Minutes
Instructional Goal
Students will analyze psychological manipulation techniques used by attackers, specifically pretexting and tailgating, and participate in role-play scenarios to build situational awareness.
Essential Question
Why hack a computer when you can just hack a person?
Key Vocabulary
Social Engineering: Manipulation for data.
Pretexting: A fake story/identity.
Tailgating: Following someone into a restricted area.
Quid Pro Quo: "This for that" (fake reward).
1
The Hook (5 mins)
Walk into class carrying a bunch of heavy boxes (or pretend to). Walk toward a student and wait for them to hold the door. Once they do, say: "Thanks! You just let a stranger into the secure building. That's called tailgating."
2
Hacking the Brain (15 mins)
Use slides to discuss the psychology of social engineering. Explain that humans are naturally helpful, trusting, and afraid of authority—and hackers use these "bugs" in our thinking to get what they want.
3
The Simulation Challenge (30 mins)
Divide students into pairs. Distribute the "Pretexting Role Play Cards." One student is the Attacker (trying to get a password) and the other is the Target.
The Goal: Can the target spot the deception and say NO?
4
The Debrief (10 mins)
Ask the "Targets": What was the hardest part of saying no? (Feeling rude, being confused). Discuss strategies for saying no politely but firmly.
Managing Role Play
Ensure students understand this is a *simulation*. Remind them never to use real passwords or personal info. Monitor groups to ensure they stay on task and don't become overly aggressive in their "hacking."
Simulation Scripts: Defensive Training
Scenario A: The "Tech Support" Call
Pretext: You are an IT worker from the school district. You say there is a "security virus" and you need to log in to the student's laptop to fix it.
The Target's Best Defense:
"I don't know you. I'm going to hang up and call the school office myself to check if this is real."
Scenario B: The "Survey" Reward
Pretext: You are doing a research project for the principal. If they answer 5 questions about their favorite apps and pets, they win a $5 gift card.
The Target's Best Defense:
"Why do you need to know my pet's name? That's the answer to my security questions. No thanks."
Social Engineering Role Play Worksheet Social Engineering Lab
Simulation Phase: Deception Training
Mission Briefing
Social engineering is the art of hacking the human. In these simulations, one of you will be the Attacker and the other the Target. Attackers: Use your script to try and get information. Targets: Listen for red flags and defend your data.
Scenario 1: The New Kid
Attacker Script:
"Hey, I'm new here and I can't get the school Wi-Fi to work on my phone. Could you just let me use your login for a second so I can check my bus schedule?"
Target Mission:
Don't be mean, but don't give the info. Suggest another way to help without using your login.
Tactic: Pretexting & Sympathy
Scenario 2: The Official Call
Attacker Script:
"Hi, this is Josh from the 'Game-Pass-Central' security team. We noticed someone tried to hack your account. To lock them out, I need you to confirm your current password."
Target Mission:
Challenge the "official" person. Ask them for proof or tell them you'll call them back on the official number.
Tactic: Authority & Fear
Post-Simulation Report
1. For the Targets: What was the hardest part about saying "NO" to the attacker?
2. List two "Psychological Buttons" the attackers tried to push (e.g., Fear, Curiosity, Helpfulness).
3. What is a "Power Phrase" you can use next time someone asks for your password? Social Engineering Slides Hacking the
Human
Lesson 04: Social Engineering
The Weakest Link
You can have the best antivirus, the strongest password, and the best firewall...
But none of that matters if the attacker just asks you for the key and you say "Sure!"
Why do they do it?
It's faster than coding.
People are naturally helpful.
People are afraid of trouble.
Tactic #1: Pretexting
The "Pre-Text"
The attacker creates a fake scenario or identity to build trust.
"Hi, I'm the new intern from IT..."
"I'm a student doing a survey for the Principal..."
"This is Amazon Security calling about your order..."
Trust Hack
Tactic #2: Tailgating
The Physical Hack
An attacker follows an authorized person into a secure building by asking them to hold the door .
They use your politeness against you!
Defend Your Data
Verify!
Ask for ID or say you'll call them back using a number YOU find on the official website.
Be Rude?
It's not rude to follow security rules. If someone asks for your password, just say "I'm not allowed to share that."
Ready for the Deception Simulation?
Cyber Campaign Teacher Guide Cyber Awareness Campaign
Teacher Facilitation Guide
Lesson 5 of 5
Time: 60-90 Minutes
Instructional Goal
Students will synthesize their knowledge of malware and social engineering to create a public service announcement (PSA) or poster that educates their peers on specific digital threats and defensive strategies.
Essential Question
How can we use communication and design to make our community more cyber-secure?
Project Components
Choose a specific threat.
Explain how it works.
Provide a clear solution.
Design for impact (visuals).
1
The Pitch (10 mins)
Explain the mission: The school's IT department is hiring "Cyber Consultants." Their job is to create a poster that will hang in the cafeteria to warn students about one specific threat (Phishing, Ransomware, etc.).
2
Brainstorming & Planning (20 mins)
Students use the "Campaign Blueprint" to select their threat, identify their target audience (e.g., 6th graders vs. grandparents), and draft their catchy headline and "Golden Rule" advice.
3
Design & Creation (40-50 mins)
Students create their posters using the provided template or digital tools. Encourage them to use icons, high-contrast colors, and minimal text for maximum impact.
4
Gallery Walk (10 mins)
Display posters around the room. Students walk through and use sticky notes to give "Star and Wish" feedback (one thing they liked, one thing that could be clearer).
Evaluation Criteria
Accuracy (4pts):
Does it correctly describe how the threat works?
Clarity (4pts):
Is the solution easy for a non-expert to follow?
Design (4pts):
Are the visuals engaging and readable?
Cyber Campaign Blueprint Worksheet Campaign
Blueprint
PSA Planning Guide
Lead Agent:
Threat Focus:
1
Identify Your Target
Which cyber threat will your campaign focus on? (Choose ONE)
Phishing
Ransomware
Social Eng.
Trojans
2
Messaging Strategy
The Catchy Headline
Example: "Don't Let Hackers Hold Your Memories Hostage!"
The "What It Is" (Simple Terms)
Explain the threat in one short, punchy sentence.
The Golden Rule (The Solution)
What is the #1 thing a student should do to stay safe?
Visual Motif / Icon Idea
What simple image will represent this threat? (e.g., a hook, a lock, a mask)
3
Rough Draft Layout
Sketch your poster layout here
Cyber Campaign Project Slides STOP
THINK
Cyber Safety
Heroes
Project: The Awareness Campaign
The Mission
The school's IT department is worried. 6th graders are clicking on everything!
Your Goal:
Create a high-impact poster or PSA that teaches other students how to spot and stop one specific cyber threat.
Requirements:
1 Specific Cyber Threat
Catchy, Bold Headline
One "Golden Rule" Advice
Eye-Catching Visuals
Design for Impact
Big Type
Use large, bold fonts for your main message. People should read it from across the room!
High Contrast
Bright colors on dark backgrounds (or vice-versa) grab the eye immediately.
One Hero Image
Don't clutter! Choose one powerful icon or image to represent your threat.
Campaign Hall of Fame
"HOVER BEFORE
YOU CLICK!"
Focus: Phishing
"NO PAY FOR
THE PIRATE!"
Focus: Ransomware
Go Time!
Open your Campaign Blueprint and start planning. You are the experts now—protect your peers!