Python']Python and Malware: Developing Stealth and Evasive Malware without Obfuscation

被引:1
|
作者
Koutsokostas, Vasilios [1 ]
Patsakis, Constantinos [1 ,2 ]
机构
[1] Univ Piraeus, Inst Problem Solving, Dept Informat, Piraeus, Greece
[2] Athena Res Ctr, Informat Management Syst Inst, Artemidos 6, Maroussi 15125, Greece
来源
SECRYPT 2021: PROCEEDINGS OF THE 18TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY | 2021年
基金
欧盟地平线“2020”;
关键词
Malware; Antivirus; !text type='Python']Python[!/text; Evasion; Sandbox;
D O I
10.5220/0010541501250136
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the continuous rise of malicious campaigns and the exploitation of new attack vectors, it is necessary to assess the efficacy of the defensive mechanisms used to detect them. To this end, the contribution of our work is twofold. First, it introduces a new method for obfuscating malicious code to bypass all static checks of multi-engine scanners, such as VirusTotal. Interestingly, our approach to generating the malicious executables is not based on introducing a new packer but on the augmentation of the capabilities of an existing and widely used tool for packaging Python, PyInstaller but can be used for all similar packaging tools. As we prove, the problem is deeper and inherent in almost all antivirus engines and not PyInstaller specific. Second, our work exposes significant issues of well-known sandboxes that allow malware to evade their checks. As a result, we show that stealth and evasive malware can be efficiently developed, bypassing with ease state of the art malware detection tools without raising any alert.
引用
收藏
页码:125 / 136
页数:12
相关论文
共 31 条