Research Article

Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images

Table 4

Inferred script functionality by size.

Obfuscation methodMultiplication factor Corr. predicted

No obfuscation12,116/2,355 (89.85%)
ASCII encoding4.194452,040/2,355 (85.14%)
Token-based2.028521,999/2,355 (84.88%)
String-based1.794991,939/2,355 (82.34%)
AbstractSyntaxTree1.096722,005/2,355 (85.14%)
Overallā€”85.77%