PowerShell Malware Analysis Using a Novel Malware Rating System

David Arnold, Charlotte David, Jafar Saniie · 2022

Recent high-profile cyberattacks highlight an increased use of social engineering attacks and ransomware by hackers worldwide. These attacks target human operators directly, bypassing many of the cyber-safeguards developed through years of malware analysis. In response to these challenges, many organizations have turned to white-hat hackers and penetration testing to identify potential weaknesses and reinforce cyber-safety protocols. To assist in the threat evaluation process, malware rating systems are often used to highlight the danger and potential damage malware may cause. Current malware rating systems focus on assigning a danger score for malware based on its ability to move throughout the network, damage system resources, and evade detection. Due to the increased reliance on social engineering, a new malware rating system is proposed that incorporates malware deceitfulness as a means to trick human operators. The novel rating system will score malware based on its Stealth, Ease of Creation, Deceitfulness, Versatility, Instantaneousness, and Persistence. This system provides operators with insight into each key characteristics as opposed to a single value. To showcase the malware evaluation process, different PowerShell Reverse Bind Shell malwares are rated based on the proposed criteria.

Read the paper · More papers on PaperTik