发明名称 HOOKING NONEXPORTED FUNCTIONS BY THE OFFSET OF THE FUNCTION
摘要 <p>Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes accessing offset data associated with a binary executable, the offset data including an offset of a nonexported function; and modifying instructions at the offset. In another aspect, a method includes analyzing a reference generated for a binary executable, identifying a unique identifier for the binary executable, determining an offset of a nonexported function in the binary executable, and generating offset data that includes the offset and the unique identifier.</p>
申请公布号 EP2507737(A2) 申请公布日期 2012.10.10
申请号 EP20100835122 申请日期 2010.12.02
申请人 MCAFEE, INC. 发明人 NOJIRI, DAISUKE
分类号 G06F7/493;G06F13/14;G06F21/54;G06F21/56 主分类号 G06F7/493
代理机构 代理人
主权项
地址
您可能感兴趣的专利