Minerva automatically unpacks system-wide Windows malware into PE files with valid import tables and patched API calls, and its evaluation shows fewer spurious API calls and more detected multi-process propagation than the compared unpacker.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2019 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
Precise system-wide concatic malware unpacking
Minerva automatically unpacks system-wide Windows malware into PE files with valid import tables and patched API calls, and its evaluation shows fewer spurious API calls and more detected multi-process propagation than the compared unpacker.