Journal of System and Computer Engineering
Vol 7 No 2 (2026): JSCE: April 2026

Investigating LOLBAS-Based Malware Using Hybrid Analysis: A Case Study of PowerShell-Driven Fileless Execution

Rosmiati, Rosmiati (Unknown)
Amar, Muh. Ikhsan (Unknown)
Arsyad, Muhammad Arham (Unknown)
Hariani, Hariani (Unknown)



Article Info

Publish Date
30 Apr 2026

Abstract

This study aims to identify and understand the technical characteristics of the malware output.exe, obtained from the MalwareBazaar repository, through a hybrid reverse engineering approach. This method combines static and dynamic analyses to provide a comprehensive understanding of the malware’s internal structure, execution behavior, and evasion techniques. Static analysis revealed the invocation of system functions such as CreateProcessW and RegSetValueExA, as well as the use of syscall to execute PowerShell commands directly, indicating the implementation of the LOLBAS (Living off the Land Binaries and Scripts) technique. Dynamic analysis using CAPE Sandbox confirmed the malware’s actual behavior, including process injection into legitimate processes such as svchost.exe, launching powershell.exe for data compression, and establishing network communication via Discord Webhook for data exfiltration. Integration of both analyses shows that output.exe functions as an information stealer with fileless execution and advanced persistence mechanisms. These findings demonstrate that the hybrid analysis approach is effective in identifying modern malware that leverages legitimate system components to evade traditional signature-based detection methods.

Copyrights © 2026






Journal Info

Abbrev

JSCE

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management

Description

Programming Languages Algorithms and Theory Computer Architecture and Systems Artificial Intelligence Computer Vision Machine Learning Systems Analysis Data Communications Cloud Computing Object Oriented Systems Analysis and Design Computer and Network Security Data ...