PowerDrive: Accurate De-obfuscation and Analysis of PowerShell Malware

被引:14
|
作者
Ugarte, Denis [1 ]
Maiorca, Davide [1 ]
Cara, Fabrizio [1 ]
Giacinto, Giorgio [1 ]
机构
[1] Univ Cagliari, Dept Elect & Elect Engn, Cagliari, Italy
关键词
D O I
10.1007/978-3-030-22038-9_12
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
PowerShell is nowadays a widely-used technology to administrate and manage Windows-based operating systems. However, it is also extensively used by malware vectors to execute payloads or drop additional malicious contents. Similarly to other scripting languages used by malware, PowerShell attacks are challenging to analyze due to the extensive use of multiple obfuscation layers, which make the real malicious code hard to be unveiled. To the best of our knowledge, a comprehensive solution for properly de-obfuscating such attacks is currently missing. In this paper, we present PowerDrive, an open-source, static and dynamic multi-stage de-obfuscator for PowerShell attacks. PowerDrive instruments the PowerShell code to progressively de-obfuscate it by showing the analyst the employed obfuscation steps. We used PowerDrive to successfully analyze thousands of PowerShell attacks extracted from various malware vectors and executables. The attained results show interesting patterns used by attackers to devise their malicious scripts. Moreover, we provide a taxonomy of behavioral models adopted by the analyzed codes and a comprehensive list of the malicious domains contacted during the analysis.
引用
收藏
页码:240 / 259
页数:20
相关论文
共 35 条
  • [31] IMSindel: An accurate intermediate-size indel detection tool incorporating de novo assembly and gapped global-local alignment with split read analysis
    Daichi Shigemizu
    Fuyuki Miya
    Shintaro Akiyama
    Shujiro Okuda
    Keith A Boroevich
    Akihiro Fujimoto
    Hidewaki Nakagawa
    Kouichi Ozaki
    Shumpei Niida
    Yonehiro Kanemura
    Nobuhiko Okamoto
    Shinji Saitoh
    Mitsuhiro Kato
    Mami Yamasaki
    Tatsuo Matsunaga
    Hideki Mutai
    Kenjiro Kosaki
    Tatsuhiko Tsunoda
    [J]. Scientific Reports, 8
  • [32] Publisher Correction: IMSindel: An accurate intermediate-size indel detection tool incorporating de novo assembly and gapped global-local alignment with split read analysis
    Daichi Shigemizu
    Fuyuki Miya
    Shintaro Akiyama
    Shujiro Okuda
    Keith A. Boroevich
    Akihiro Fujimoto
    Hidewaki Nakagawa
    Kouichi Ozaki
    Shumpei Niida
    Yonehiro Kanemura
    Nobuhiko Okamoto
    Shinji Saitoh
    Mitsuhiro Kato
    Mami Yamasaki
    Tatsuo Matsunaga
    Hideki Mutai
    Kenjiro Kosaki
    Tatsuhiko Tsunoda
    [J]. Scientific Reports, 8
  • [33] IMSindel: An accurate intermediate-size indel detection tool incorporating de novo assembly and gapped global-local alignment with split read analysis (vol 8, 2018)
    Shigemizu, Daichi
    Miya, Fuyuki
    Akiyama, Shintaro
    Okuda, Shujiro
    Boroevich, Keith A.
    Fujimoto, Akihiro
    Nakagawa, Hidewaki
    Ozaki, Kouichi
    Niida, Shumpei
    Kanemura, Yonehiro
    Okamoto, Nobuhiko
    Saitoh, Shinji
    Kato, Mitsuhiro
    Yamasaki, Mami
    Matsunaga, Tatsuo
    Mutai, Hideki
    Kosaki, Kenjiro
    Tsunoda, Tatsuhiko
    [J]. SCIENTIFIC REPORTS, 2018, 8