Research Article

Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images

Table 6

Detection results for StegExpose in “fast” mode.

Invoke-PSImage Mode-1

ScriptsCorrect detec.FN rate (ms) (ms) (%)
Deobfuscated3860/4641 (83.17%)781/4641 (16.83%)1.371.3759
Obfuscated1017/4018 (25.31%)3001/4018 (74.69%)0.440.4493
Overall56.32%43.68%0.940.9475

Invoke-PSImage Mode-2
ScriptsCorrect detec.FN rate (ms) (ms) (%)
Deobfuscated (256 × 256)3649/5000 (72.98%)1351/5000 (27.02%)12212210163
Deobfuscated (512 × 512)2852/5000 (57.04%)2148/5000 (42.96%)480.27480.2725965
Deobfuscated (1024 × 1024)2902/5000 (58.04%)2098/5000 (41.96%)1606.091606.09104000
Obfuscated (256 × 256)3694/5000 (73.88%)1306/5000 (26.12%)118.33118.333841
Obfuscated (512 × 512)2859/5000 (57.18%)2141/5000 (42.82%)364.44364.449719
Obfuscated (1024 × 1024)2792/5000 (55.84%)2208/5000 (44.16%)1694.71694.739816
Overall62.49%37.51%730.97730.9732251

ScriptsCorrect detec.FP rate (ms) (ms) (%)
Clean (256 × 256)4905/5000 (98.1%)95/5000 (1.9%)6.32N/AN/A
Clean (512 × 512)4966/5000 (99.32%)34/5000 (0.68%)16.44N/AN/A
Clean (1024 × 1024)4912/5000 (98.24%)88/5000 (1.76%)140.67N/AN/A
Overall98.55%1.45%54.48N/AN/A