Research Article

Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images

Table 7

Detection results for McAfee SAT (only files of size 256 × 256 can be tested).

Invoke-PSImage Mode-1

ScriptsCorrect detec.FN rate (ms)Conf. levelScore
Deobfuscated3064/4641 (66.02%)1577/4641 (33.98%)5.59Low: 0, medium: 2055, high: 2586544.07
Obfuscated822/4018 (20.46%)3196/4018 (79.54%)17.35Low: 0, medium: 3892, high: 126100.83
Overall44.88%55.12%11.47N/A322.45

Invoke-PSImage Mode-2
ScriptsCorrect detec.FN rate (ms)Conf. levelScore
Deobfuscated4482/5000 (89.64%)518/5000 (10.36%)1343.29Low: 0, medium: 2476, high: 2524426.87
Obfuscated4365/5000 (87.3%)635/5000 (12.7%)1337.54Low: 0, medium: 2476, high: 2524417.26
Overall88.47%11.53%1340.41N/A422.06

Clean4927/5000 (98.54%)3/5000 (1.46%)1097.37Low: 0, medium: 4991, high: 932.03