PowerDecode: a PowerShell Script Decoder Dedicated to Malware Analysis

Giorgio Giacinto
Penultimo
;
Davide Maiorca
Ultimo
2021-01-01

Abstract

In recent years, PowerShell-based attacks have been widely employed to compromise systems’ security. Attackers can easily hide such malicious scripts in file formats (e.g., Office document macros) that can be easily delivered via large-scale spam mail campaigns. Moreover, attackers employ obfuscation techniques that make the PowerShell code able to evade the most common anti-malware protections and perform unauthorized actions that will target the confidentiality, integrity and availability of an information system. In this paper, we present PowerDecode, an open-source module for the de-obfuscation and the analysis of PowerShell scripts. In particular, this module receives a script as an input and returns its obfuscated layers, its original de-obfuscated variant and a report about possible malicious activities. We tested PowerDecode on almost 3000 malicious scripts and the attained results showed significantly improved de-obfuscation performances in comparison to state-of-the-art systems. More specifically, PowerDecode was able to resolve multiple types of obfuscation and collect important information about attacks, such as malicious URLs and IP addresses contacted by malware. Finally, PowerDecode can be easily integrated in other malware analysis systems, and can represent a precious aid to identify malicious activities.
2021
Inglese
Proceedings of the Italian Conference on Cybersecurity, ITASEC 2021
CEUR-WS.org
Aachen
GERMANIA
Alessandro Armando, Michele Colajanni
2940
219
232
14
http://ceur-ws.org/Vol-2940/paper19.pdf
Italian Conference on Cybersecurity (ITASEC 2021)
Comitato scientifico
7-9 Aprile 2021
Online
internazionale
scientifica
PowerShell; Malware; Obfuscation
no
4 Contributo in Atti di Convegno (Proceeding)::4.1 Contributo in Atti di convegno
Mario Malandrone, Giuseppe; Virdis, Giovanni; Giacinto, Giorgio; Maiorca, Davide
273
4
4.1 Contributo in Atti di convegno
open
info:eu-repo/semantics/conferencePaper
File in questo prodotto:
File Dimensione Formato  
malandrone21-itasec.pdf

accesso aperto

Tipologia: versione editoriale
Dimensione 1.33 MB
Formato Adobe PDF
1.33 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Questionario e social

Condividi su:
Impostazioni cookie