Security News PowerShell Obfuscation Ups the Ante on Antivirus

silversurfer

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Well-known
Aug 17, 2014
10,154
A new obfuscation technique has been spotted that uses the features of PowerShell, a tool that comes built in to Microsoft Windows. Analysis from Cylance shows that the tactic succeeds in bypassing most antivirus products.

Cylance researchers stumbled across a malware file using a PowerShell obfuscation method while looking into a set of malicious scripts that had low antivirus detection. The file was a ZIP file containing both a PDF document and VBS script, and it was flagged by just three antivirus products.

It takes a page from other common obfuscation techniques, which include using packers to compress a malware program; encryption to hide its unique strings of code; or techniques that mutate malware cosmetics, such as the overall number of bytes in the program. All of these alter the hash and the signature of the malware so that common antivirus tools won’t flag it as a known malicious agent.

“Obfuscation is a term of art that describes a set of techniques used to evade antivirus products that rely heavily on signatures,” explained researchers at Cylance, in a technical analysis posted Wednesday on the tactic. “These techniques change the overall structure of a piece of malware without altering its function. Often, this has the overall result of creating layers which act to bury the ultimate payload, like the nested figures in a Russian doll.”
 

artek

Level 5
Verified
May 23, 2014
236
I was gonna say the only thing missing from a Cylance thread is Lockdown, but he beat me to the punch.
 
  • Like
Reactions: given
D

Deleted Member 3a5v73x

Nice analysis. But yeah, if there isn't someone techy in family, regular users won't know how to disable these attack vectors. Only little education what files with what extensions shouldn't be run might help elders. I vote for SRP myself and Hard_Configurator by Andy, but I understand that elders won't have a clue, my best suggestion is just to use Windows Defender or some most popular AV suite, older people shouldn't use Cylance.
 

artek

Level 5
Verified
May 23, 2014
236
2cyrur.jpg
 
  • Like
Reactions: Andy Ful and given
D

Deleted member 178

The file was a ZIP file containing both a PDF document and VBS script, and it was flagged by just three antivirus products.
the idiot tested it on VT ROFL

Now in real world (not VT), go find me an AV without some sort of BB/HIPS to block the dropper...Immunet maybe LOOOL

Again, the shady Cylance deceptive marketing via bashing other AVs, , seems they need pushing their sales LOL
 
Last edited by a moderator:
D

Deleted member 178

I was gonna say the only thing missing from a Cylance thread is Lockdown, but he beat me to the punch.
i was going to say, what was also missed in the thread was Artek's off-topic comments on Lockdown's comments, but he beat me to the punch. LOL

itwt
 
  • Like
Reactions: given

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top