PowerPeeler: A Precise and General Dynamic Deobfuscation Method for PowerShell Scripts
Ruijie Li, Chenyang Zhang, Huajun Chai, Lingyun Ying, Haixin Duan, Jun Tao
摘要
PowerShell is a powerful and versatile task automation tool. Unfortunately, it is also widely abused by cyber attackers. To bypass malware detection and hinder threat analysis, attackers often employ diverse techniques to obfuscate malicious PowerShell scripts. Existing deobfuscation tools suffer from the limitation of static analysis, which fails to simulate the real deobfuscation process accurately. Accurate, complete, and robust PowerShell script deobfuscation is still a challenging problem. In this paper, we propose PowerPeeler. To the best of our knowledge, it is the first dynamic PowerShell script deobfuscation approach at the instruction level. It utilizes expression-related Abstract Syntax Tree (AST) nodes to identify potential obfuscated script pieces. Then, PowerPeeler correlates the AST nodes with their corresponding instructions and monitors the script's entire execution process. Subsequently, PowerPeeler dynamically tracks the execution of these instructions and records their execution results. Finally, PowerPeeler stringifies these results to replace the corresponding obfuscated script pieces and reconstruct the deobfuscated script. To evaluate the effectiveness of PowerPeeler, we collect 1,736,669 real-world malicious PowerShell samples and distill two high-quality datasets with diversity obfuscation methods: D-Script with 4,264 obfuscated script files and D-Cmdline with 381 obfuscated samples using PowerShell command-line interface. We compare Power-Peeler with five state-of-the-art deobfuscation tools and GPT-4.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security AnalysisDongchao Zhou, Lingyun Ying, Huajun Chai, Dongbin WangNDSS 2026 · 被引用 3 次
- FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based FirmwareRunhao Liu, Jiarun Dai, Haoyu Xiao, Yuan Zhang 等NDSS 2026 · 被引用 1 次
- AutoMalDesc: Large-Scale Script Analysis for Cyber Threat ResearchAlexandru-Mihai Apostu, Andrei Preda, Alexandra Daniela Damir, Diana Bolocan 等AAAI 2026
它引用的顶会 Paper4
- Enhancing State-of-the-art Classifiers with API Semantics to Detect Evolved Android MalwareXiaohan Zhang, Yuan Zhang, Ming Zhong, Daizong Ding 等CCS 2020 · 被引用 173 次
- Effective and Light-Weight Deobfuscation and Semantic-Aware Attack Detection for PowerShell ScriptsZhenyuan Li, Qi Alfred Chen, Chunlin Xiong, Yan Chen 等CCS 2019 · 被引用 38 次
- API2Vec: Learning Representations of API Sequences for Malware DetectionLei Cui, Jiancong Cui, Yuede Ji, Zhiyu Hao 等ISSTA 2023 · 被引用 37 次
- Does Every Second Count? Time-based Evolution of Malware Behavior in SandboxesAlexander Küchler, Alessandro Mantovani, Yufei Han, Leyla Bilge 等NDSS 2021
相关 Paper
- PSDissect: A CFG-Guided, Semantics-Preserving Interactive Deobfuscation Framework for PowerShell ScriptsYifeng Fu, Jingfeng Xue, Weijie Han, Yong Wang 等CCS 2026
- Can LLMs Obfuscate Code? A Systematic Analysis of Large Language Models into Assembly Code ObfuscationSeyedreza Mohseni, Seyedali Mohammadi, Deepa Tilwani, Yash Saxena 等AAAI 2025 · 被引用 6 次
- JsDeObsBench: Measuring and Benchmarking LLMs for JavaScript DeobfuscationGuoqiang Chen, Xin Jin, Zhiqiang LinCCS 2025
- CmdCaliper: A Semantic-Aware Command-Line Embedding Model and Dataset for Security ResearchSian-Yao Huang, Cheng-Lin Yang, Che-Yu Lin, Chun-Ying HuangEMNLP 2024 · 被引用 1 次
- Adversarial Authorship Attribution for DeobfuscationWanyue Zhai, Jonathan Rusert, Zubair Shafiq, Padmini SrinivasanACL 2022 · 被引用 7 次
