Unicornを使ったマルウェア解析の効率化
ID: ea57b885-1e90-58ef-a3a5-d68b8932cbe1
STIX ID: report--ea57b885-1e90-58ef-a3a5-d68b8932cbe1
Feed Name: IIJ Security Diary
Threat Score
この記事はUnicornエミュレータの基礎と、マルウェア解析における利用例—特にAPI Hashing(ハッシュ化されたAPI名の復元)解析—を解説する技術記事です。Unicornを用いたメモリ/レジスタの準備、コードエミュレーション手順、具体的なPython/IDAスクリプト例を示し、ロード時に用いられるハッシュ算出関数の特定と自動化による解析効率化を紹介しています。
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
