Invention Grant
- Patent Title: Hooking nonexported functions by the offset of the function
- Patent Title (中): 通过函数的偏移来挂接不输出的函数
-
Application No.: US12629330Application Date: 2009-12-02
-
Publication No.: US08484753B2Publication Date: 2013-07-09
- Inventor: Daisuke Nojiri
- Applicant: Daisuke Nojiri
- Applicant Address: US CA Santa Clara
- Assignee: McAfee, Inc.
- Current Assignee: McAfee, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for obfuscated malware. In one aspect, a method includes accessing offset data associated with a binary executable, the offset data including an offset of a nonexported function; and modifying instructions at the offset. In another aspect, a method includes analyzing a reference generated for a binary executable, identifying a unique identifier for the binary executable, determining an offset of a nonexported function in the binary executable, and generating offset data that includes the offset and the unique identifier.
Public/Granted literature
- US20110131657A1 HOOKING NONEXPORTED FUNCTIONS BY THE OFFSET OF THE FUNCTION Public/Granted day:2011-06-02
Information query