计算机科学
有效载荷(计算)
逃避(道德)
沙盒(软件开发)
装载机
可执行文件
混淆
操作系统
Rootkit
恶意软件
计算机安全
过程(计算)
嵌入式系统
生物
网络数据包
免疫学
免疫系统
作者
Giorgio Bernardinetti,Dimitri Di Cristofaro,Giuseppe Bianchi
标识
DOI:10.1007/s11416-022-00417-2
摘要
The ability to evade Antivirus analyses is a highly coveted goal in the cybersecurity field, especially in the case of Red Team operations where advanced external threats against a target infrastructure are performed. In this paper we present the design and implementation of PEzoNG, a framework for automatically creating stealth binaries that target a very low detection rate in a Windows environment. PEzoNG features a custom loader for Windows binaries, polymorphic obfuscation, a payload decryption process and a number of anti-sandbox and anti-analysis evasion mechanisms, including a novel user space unhooking technique. In addition, the custom loader supports a large amount of Windows executable files, and features stealth and advanced memory allocation schemes. We evaluate the effectiveness of PEzoNG by testing various malicious payloads against up to 29 commercial Antivirus solutions, and we highlight and discuss the assets and differences of PEzoNG with respect to similar tools.
科研通智能强力驱动
Strongly Powered by AbleSci AI