HomeSecurityDetection and analysis of malicious scripts

Detection and analysis of malicious scripts

Commonly known malware is usually compiled, translating the source code into machine language.

script analysis

Compilation occurs when the computer takes human-readable code and converts it into instructions that the processor can understand, creating static files. For example, it compiles C or C++ code into executable files such as .exe or .dll for Windows.

What are malicious scripts?

Scripts have become increasingly popular in recent years, mainly because they effectively evade traditional endpoint and are easy to hide.

Hackers in two ways:

  • They add a script that executes an attack step in compiled malware to execute a command or download a payload.
  • They create malware directly using a scripting language. An example is Lu0bot, which is written in Node.js.

Specifically, WSHRAT is a RAT written in JavaScript, known for using multiple JS calls, creating a complex structure. At the same time, Lu0Bot is a botnet written in Node.js and is distinguished by its packaging with a NodeJS interpreter. STRRAT also belongs to the same category , a RAT written in JavaScript that belongs to the category of compiled Java-based malware, which is decompressed upon execution. Finally, Jsoutprox is a script-based backdoor written in JavaScript, providing hidden access to the system.

Read more: Monocle: Open-Source LLM for binary analysis search

Despite effective detection methods, such as YARA rules for compiled malware, modern threats such as Mirai and FormBook still persist. However, hackers are now turning to the use of malicious scripts, which evade traditional endpoint detection and are easier to hide. These scripts can be part of the compiled malware or written entirely in scripting languages, such as Node.js, JavaScript, and PowerShell.

Characteristics of malicious scripts

Key characteristics of malicious scripts include fileless execution, running in memory without leaving a trace, and using built-in operating system utilities. They often leverage languages ​​such as JavaScript, PowerShell, batch scripts, VBScript, and JScript on Windows, as well as shell scripts on Linux. Some of these scripts require additional runtime environments or software, such as JavaScript, which requires a web browser or Node.js server, and Python which requires an installed interpreter.


Scripting Language Execution Environment

JavaScript Web browsers (eg, Chrome, Firefox), Node.js runtime

JScript Windows OS, Internet Explorer

VBScript Windows OS, Microsoft Office applications (eg, Word, Excel)

PowerShell Windows OS, built-in Windows tool

Batch Scripts Windows OS, command-line interface

Shell Scripts (Bash) Unix/Linux OS, command-line interface

Python Scripts Cross-platform (Windows, macOS, Linux)

How to analyze malicious scripts and script-based malware (Malware)?

For script analysis, you have two main options: static and dynamic analysis. Static analysis focuses on examining the code base line by line without executing it, while dynamic analysis involves executing the script, using debuggers and script tracers to monitor its behavior on a system.

malicious scripts

See also: Galaxy Z Fold 6 and Flip 6 adopt dual-screen for translation, like the Pixel Fold

Dynamic methods, such as sandboxing, are generally considered more effective than static methods, especially for malware , because reverse-engineering an opaque codebase is incredibly time-consuming. This complex analysis changes variable names, encodes strings, and adds layers of complexity, such as encryption. In such cases, it is more practical to focus on the execution flow and behavior of the program rather than trying to decode a not-so-obvious source code.

Source: any.run

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS