Research Article

Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images

Table 5

Detection results for StegExpose in “default” mode.

Invoke-PSImage Mode-1

ScriptsCorrect detec.FN rate (ms) (ms) (%)
Deobfuscated4429/4641 (95.43%)212/4641 (4.57%)1.561.5656
Obfuscated1649/4018 (41.04%)2369/4018 (58.96%)3.723.7291
Overall70.19%29.81%2.562.5672

Invoke-PSImage Mode-2
ScriptsCorrect detec.FN rate (ms) (ms) (%)
Deobfuscated (256 × 256)4850/5000 (97%)150/5000 (3%)164.25164.2511614
Deobfuscated (512 × 512)4579/5000 (91.58%)421/5000 (8.42%)824.05824.0531470
Deobfuscated (1024 × 1024)4600/5000 (92%)400/5000 (8%)3308.113308.11125795
Obfuscated (256 × 256)4816/5000 (96.32%)184/5000 (3.68%)183.74183.744380
Obfuscated (512 × 512)4498/5000 (89.96%)502/5000 (10.04%)831.91831.9111848
Obfuscated (1024 × 1024)4525/5000 (90.05%)475/5000 (9.5%)3199.813199.8148231
Overall92.89%7.11%1418.651418.6538890

ScriptsCorrect detec.FP rate (ms) (ms)
Clean (256 × 256)4885/5000 (97.7%)115/5000 (2.3%)166.4N/AN/A
Clean (512 × 512)4897/5000 (97.94%)103/5000 (2.06%)831.82N/AN/A
Clean (1024 × 1024)4831/5000 (96.62%)169/5000 (3.38%)3261.14N/AN/A
Overall97.42%2.58%1419.79N/AN/A