loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: Vasilios Koutsokostas 1 and Constantinos Patsakis 2 ; 1

Affiliations: 1 Institute of Problem Solving, Department of Informatics, University of Piraeus, Piraeus, Greece ; 2 Information Management Systems Institute, Athena Research Center, Artemidos 6, Marousi 15125, Greece

Keyword(s): Malware, Antivirus, Python, Evasion, Sandbox.

Abstract: With the continuous rise of malicious campaigns and the exploitation of new attack vectors, it is necessary to assess the efficacy of the defensive mechanisms used to detect them. To this end, the contribution of our work is twofold. First, it introduces a new method for obfuscating malicious code to bypass all static checks of multi-engine scanners, such as VirusTotal. Interestingly, our approach to generating the malicious executables is not based on introducing a new packer but on the augmentation of the capabilities of an existing and widely used tool for packaging Python, PyInstaller but can be used for all similar packaging tools. As we prove, the problem is deeper and inherent in almost all antivirus engines and not PyInstaller specific. Second, our work exposes significant issues of well-known sandboxes that allow malware to evade their checks. As a result, we show that stealth and evasive malware can be efficiently developed, bypassing with ease state of the art malware dete ction tools without raising any alert. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 34.238.242.168

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Koutsokostas, V. and Patsakis, C. (2021). Python and Malware: Developing Stealth and Evasive Malware without Obfuscation. In Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-524-1; ISSN 2184-7711, SciTePress, pages 125-136. DOI: 10.5220/0010541501250136

@conference{secrypt21,
author={Vasilios Koutsokostas. and Constantinos Patsakis.},
title={Python and Malware: Developing Stealth and Evasive Malware without Obfuscation},
booktitle={Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT},
year={2021},
pages={125-136},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010541501250136},
isbn={978-989-758-524-1},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT
TI - Python and Malware: Developing Stealth and Evasive Malware without Obfuscation
SN - 978-989-758-524-1
IS - 2184-7711
AU - Koutsokostas, V.
AU - Patsakis, C.
PY - 2021
SP - 125
EP - 136
DO - 10.5220/0010541501250136
PB - SciTePress