Security News PowerShell Obfuscation Ups the Ante on Antivirus

silversurfer

Super Moderator
Thread author
Verified
Top Poster
Staff Member
Malware Hunter
Forum Veteran
Aug 17, 2014
12,726
123,827
8,399
A new obfuscation technique has been spotted that uses the features of PowerShell, a tool that comes built in to Microsoft Windows. Analysis from Cylance shows that the tactic succeeds in bypassing most antivirus products.

Cylance researchers stumbled across a malware file using a PowerShell obfuscation method while looking into a set of malicious scripts that had low antivirus detection. The file was a ZIP file containing both a PDF document and VBS script, and it was flagged by just three antivirus products.

It takes a page from other common obfuscation techniques, which include using packers to compress a malware program; encryption to hide its unique strings of code; or techniques that mutate malware cosmetics, such as the overall number of bytes in the program. All of these alter the hash and the signature of the malware so that common antivirus tools won’t flag it as a known malicious agent.

“Obfuscation is a term of art that describes a set of techniques used to evade antivirus products that rely heavily on signatures,” explained researchers at Cylance, in a technical analysis posted Wednesday on the tactic. “These techniques change the overall structure of a piece of malware without altering its function. Often, this has the overall result of creating layers which act to bury the ultimate payload, like the nested figures in a Russian doll.”
 
I was gonna say the only thing missing from a Cylance thread is Lockdown, but he beat me to the punch.
 
  • Like
Reactions: given
Nice analysis. But yeah, if there isn't someone techy in family, regular users won't know how to disable these attack vectors. Only little education what files with what extensions shouldn't be run might help elders. I vote for SRP myself and Hard_Configurator by Andy, but I understand that elders won't have a clue, my best suggestion is just to use Windows Defender or some most popular AV suite, older people shouldn't use Cylance.
 
2cyrur.jpg
 
  • Like
Reactions: Andy Ful and given
The file was a ZIP file containing both a PDF document and VBS script, and it was flagged by just three antivirus products.
the idiot tested it on VT ROFL

Now in real world (not VT), go find me an AV without some sort of BB/HIPS to block the dropper...Immunet maybe LOOOL

Again, the shady Cylance deceptive marketing via bashing other AVs, , seems they need pushing their sales LOL
 
Last edited by a moderator:
I was gonna say the only thing missing from a Cylance thread is Lockdown, but he beat me to the punch.
i was going to say, what was also missed in the thread was Artek's off-topic comments on Lockdown's comments, but he beat me to the punch. LOL

itwt
 
  • Like
Reactions: given