Antivirus Software Evasion
Joxean Koret, Elias Bachaalany · 2015
Antivirus evasion techniques are used by malware writers, as well as by penetration testers and vulnerability researchers, in order to bypass one or more antivirus software applications. In their software solutions, antivirus companies use various systems for statically and dynamically detecting both known and unknown malware. A key part of antivirus evasion is determining how malware is detected. This chapter covers some old and somewhat new tricks to determine how and where a known malware sample is detected. Several binary instrumentation toolkits are freely available and can be used to instrument a program, such as an antivirus command-line scanner. The taint analysis engine must be adapted for any new antivirus kernel, which usually translates into writing ugly, hard-coded workarounds for a condition that happens only with a specific antivirus engine.