发明名称 HOOKING NONEXPORTED FUNCTIONS BY THE OFFSET OF THE FUNCTION
摘要 Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes accessing offset data associated with a binary executable, the offset data including an offset of a nonexported function; and modifying instructions at the offset. In another aspect, a method includes analyzing a reference generated for a binary executable, identifying a unique identifier for the binary executable, determining an offset of a nonexported function in the binary executable, and generating offset data that includes the offset and the unique identifier.
申请公布号 EP2507737(A4) 申请公布日期 2014.04.02
申请号 EP20100835122 申请日期 2010.12.02
申请人 MCAFEE, INC. 发明人 NOJIRI, DAISUKE
分类号 G06F7/493;G06F13/14;G06F21/54;G06F21/56 主分类号 G06F7/493
代理机构 代理人
主权项
地址