2017
DOI: 10.1007/978-3-319-66332-6_10
|View full text |Cite
|
Sign up to set email alerts
|

Stealth Loader: Trace-Free Program Loading for API Obfuscation

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3
1
1

Citation Types

0
10
0

Year Published

2018
2018
2023
2023

Publication Types

Select...
3
2

Relationship

2
3

Authors

Journals

citations
Cited by 7 publications
(10 citation statements)
references
References 8 publications
0
10
0
Order By: Relevance
“…Stealth Loader was introduced by Kawakoya et al [26] for evading existing static and dynamic analysis tools. It is a program loader that loads Windows system DLLs such as kernel32.dll or ntdll.dll without leaving any trace to be detected.…”
Section: Hook Evasionmentioning
confidence: 99%
See 3 more Smart Citations
“…Stealth Loader was introduced by Kawakoya et al [26] for evading existing static and dynamic analysis tools. It is a program loader that loads Windows system DLLs such as kernel32.dll or ntdll.dll without leaving any trace to be detected.…”
Section: Hook Evasionmentioning
confidence: 99%
“…The purpose of this experiment is to show the feasibility of API Chaser against state-of-the-art evasion techniques including those introduced in academic studies. For that purpose, we collected proof-of-concept (PoC) codes of the following techniques, Process Hollowing [29], [31], AtomBombing [7], [30], PowerLoaderEx [6], Shim-based DLL Injection [40], and Stealth Loader [26]. Then, we generated synthetic malware samples based on the PoC codes and analyzed them with API Chaser.…”
Section: Synthetic Malware Experimentsmentioning
confidence: 99%
See 2 more Smart Citations
“…These techniques are used to obfuscate the positions of placed APIs by making copies of them. DLL Unlinking [16] and Stealth Loader [12] are examples of DLL position obfuscation techniques. These techniques obfuscate the locations of loaded DLLs by hiding data structures containing their metadata.…”
Section: Introductionmentioning
confidence: 99%