Revealing Packed Malware

Weidong Yan, Zheng Zhang, Nirwan Ansari · IEEE Security & Privacy · 2008

To evade malicious content detection, malware authors use packers, binary tools that instigate code obfuscation. By using executable packers, modern malware can completely bypass personal firewalls and antivirus (AV) scanners.Reverse engineering (RE) has become an important approach to analyzing a program's logic flow and internal data structures, such as system call functions. Security researchers and AV products must be able to unpack and inspect the payloads hidden within the packed programs using RE tools.

Read the paper · More papers on PaperTik