13.05.2016 Views

THE HISTORY OF THE DARKSEOUL GROUP AND THE SONY INTRUSION MALWARE DESTOVER

001398694

001398694

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CharSwap API Obfuscation<br />

This is an encoding where some character ASCII values are increased or decreased by nine.<br />

CharSwap is used for obfuscation of both APIs and regular strings. Above figure shows API de-obfuscation.<br />

The CharSwapped API names GetDriveTypeA, SetFileTime and Process32Next.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!