File Format Confusion
Created the Monday 18 March 2019. Updated 1 year, 1 month ago.
By looking the structure of the PE and the content of the file, the engine is able to detect if the file is malicious or not. For example, an heuristic engine can try to figure out if a file are using a dual extension (e.g: invoice.doc.exe) and determine the file as being malicious.
Confusing file format is another trick that can be used to bypass an AV detection specific to a file format.
Technique Identifier
Additional Resources
External Links
The resources provided below are associated links that will give you even more detailed information and research on current evasion technique. It is important to note that, while these resources may be helpful, it is important to exercise caution when following external links. As always, be careful when clicking on links from unknown sources, as they may lead to malicious content.
- https://wikileaks.org/ciav7p1/cms/files/BypassAVDynamics.pdf
- Google Code Archive - Long-term storage for Google Code Project Hosting.