Hide My Payload: An Empirical Study of Antimalware Evasion Tools

Hannes Holm, Erik Hyllienmark · 2023

This paper presents an empirical analysis of antimalware evasion techniques. A total of 29504 tests generated by 16 antimalware evasion tools were run against 100 machines protected by either Microsoft Windows Defender or Symantec Endpoint Protection. The configuration of each test was mapped to a categorization framework with 11 evasion techniques. Out of the executed tests, 54% evaded the antimalware scans and 5% provided interactive shells (i.e., remote control of victims). Out of the studied evasion techniques, using a packer, encryption (AES or RC4), or storing the payload loader in a common data format (as compared to a script or executable) had the greatest impact on evading antimalware scans, while application of custom encryption and code injection had the greatest impact on gaining shells. The results also showed that several evasion techniques curiously increased the likelihood of detection.

Read the paper · More papers on PaperTik