TY - JOUR
T1 - Mal-Xtract
T2 - 1st International Conference on Computing and Applied Informatics, ICCAI 2016
AU - Lim, Charles
AU - Syailendra Kotualubun, Yohanes
AU - Suryadi, null
AU - Ramli, Kalamullah
N1 - Publisher Copyright:
© Published under licence by IOP Publishing Ltd.
PY - 2017/3/27
Y1 - 2017/3/27
N2 - Software packer has been used effectively to hide the original code inside a binary executable, making it more difficult for existing signature based anti malware software to detect malicious code inside the executable. A new method of written and rewritten memory section is introduced to to detect the exact end time of unpacking routine and extract original code from packed binary executable using Memory Analysis running in an software emulated environment. Our experiment results show that at least 97% of the original code from the various binary executable packed with different software packers could be extracted. The proposed method has also been successfully extracted hidden code from recent malware family samples.
AB - Software packer has been used effectively to hide the original code inside a binary executable, making it more difficult for existing signature based anti malware software to detect malicious code inside the executable. A new method of written and rewritten memory section is introduced to to detect the exact end time of unpacking routine and extract original code from packed binary executable using Memory Analysis running in an software emulated environment. Our experiment results show that at least 97% of the original code from the various binary executable packed with different software packers could be extracted. The proposed method has also been successfully extracted hidden code from recent malware family samples.
UR - http://www.scopus.com/inward/record.url?scp=85017243527&partnerID=8YFLogxK
U2 - 10.1088/1742-6596/801/1/012058
DO - 10.1088/1742-6596/801/1/012058
M3 - Conference article
AN - SCOPUS:85017243527
SN - 1742-6588
VL - 801
JO - Journal of Physics: Conference Series
JF - Journal of Physics: Conference Series
IS - 1
M1 - 012058
Y2 - 14 December 2016 through 15 December 2016
ER -