Malware Detection Tool Based on Emulator State Analysis
Pavlo Rehida, Олег Савенко, Antonina Kashtalian, Anatoliy Sachenko · 2023
This work is devoted to the problem of malware detection. Main features of using sandbox technology for malware detection is considered. The problem of malware using anti-emulation techniques is shown, that allows to hide malicious behaviour. The analysis of existing solutions and features is carried out. The paper considers the basic methods for detecting emulated environment by malwares which reduces the detection percentage of such malwares. The concept of using emulator state for highlighted problem is proposed, and tool for analysis the emulator state is presented. To perform experiments, a basic emulator, instruction set, and method for emulator state analysis are presented. It was suggested to use the hash algorithm to find the different states. To complete experiments, file and its structure that will imitate the some cases of malware was presented. Paper also shows how malware developers can hide malicious actions and how hashing state can overcome this problem. Defined three different hashing strategies, that were used on prepared lists of instructions.