{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,20]],"date-time":"2026-04-20T23:28:38Z","timestamp":1776727718065,"version":"3.51.2"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2017,2,27]],"date-time":"2017-02-27T00:00:00Z","timestamp":1488153600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"name":"Brazilian National Counsel of Technological and Scientific De- velopment","award":["444487\/2014- 0"],"award-info":[{"award-number":["444487\/2014- 0"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Comput Virol Hack Tech"],"published-print":{"date-parts":[[2018,2]]},"DOI":"10.1007\/s11416-017-0292-8","type":"journal-article","created":{"date-parts":[[2017,2,27]],"date-time":"2017-02-27T07:30:10Z","timestamp":1488180610000},"page":"87-98","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["The other guys: automated analysis of marginalized malware"],"prefix":"10.1007","volume":"14","author":[{"given":"Marcus Felipe","family":"Botacin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paulo L\u00edcio","family":"de Geus","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andr\u00e9 Ricardo Abed","family":"Gr\u00e9gio","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2017,2,27]]},"reference":[{"key":"292_CR1","doi-asserted-by":"publisher","unstructured":"Afonso, V., Filho, D., Gregio, A., de\u00a0Geus, P., Jino, M.: A hybrid framework to analyze web and os malware. In: 2012 IEEE International Conference on Communications (ICC), pp. 966\u2013970 (2012). doi:\n                        10.1109\/ICC.2012.6364108","DOI":"10.1109\/ICC.2012.6364108"},{"key":"292_CR2","unstructured":"Balzarotti, D., Cova, M., Karlberger, C., Kruegel, C., Kirda, E., Vigna, G.: Efficient detection of split personalities in malware. In: NDSS 2010, 17th Annual Network and Distributed System Security Symposium. San Diego, USA (2010)"},{"key":"292_CR3","unstructured":"Bayer, U., Kruegel, C., Kirda, E.: Ttanalyze: A tool for analyzing malware. In: 15th European Institute for Computer Antivirus Research Annual Conference (2006)"},{"key":"292_CR4","unstructured":"Bellard, F.: Qemu, a fast and portable dynamic translator. In: Proceedings of the Annual Conference on USENIX Annual Technical Conference, ATEC \u201905, pp. 41\u201341. USENIX Association, Berkeley, CA, USA (2005). \n                        http:\/\/dl.acm.org\/citation.cfm?id=1247360.1247401"},{"key":"292_CR5","unstructured":"Blog, S.L.: The inevitable mode\u201464-bit zeus enhanced with tor (2013). \n                        http:\/\/securelist.com\/blog\/events\/58184\/"},{"key":"292_CR6","doi-asserted-by":"publisher","unstructured":"Corregedor, M., Von\u00a0Solms, S.: Windows 8 32 bit\u2014improved security? In: AFRICON. IEEE, pp. 1\u20135 (2013). doi:\n                        10.1109\/AFRCON.2013.6757678","DOI":"10.1109\/AFRCON.2013.6757678"},{"key":"292_CR7","doi-asserted-by":"publisher","unstructured":"Dinaburg, A., Royal, P., Sharif, M., Lee, W.: Ether: malware analysis via hardware virtualization extensions. In: Proceedings of the 15th ACM Conference on Computer and Communications Security, CCS \u201908, pp. 51\u201362. ACM, New York, NY, USA (2008). doi:\n                        10.1145\/1455770.1455779","DOI":"10.1145\/1455770.1455779"},{"key":"292_CR8","doi-asserted-by":"publisher","unstructured":"Dolan-Gavitt, B., Leek, T., Zhivich, M., Giffin, J., Lee, W.: Virtuoso: narrowing the semantic gap in virtual machine introspection. In: Proceedings of the 2011 IEEE Symposium on Security and Privacy, SP \u201911, pp. 297\u2013312. IEEE Computer Society, Washington, DC, USA (2011). doi:\n                        10.1109\/SP.2011.11","DOI":"10.1109\/SP.2011.11"},{"issue":"2","key":"292_CR9","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1145\/2089125.2089126","volume":"44","author":"M Egele","year":"2012","unstructured":"Egele, M., Scholte, T., Kirda, E., Kruegel, C.: A survey on automated dynamic malware-analysis techniques and tools. ACM Comput. Surv. 44(2), 6 (2012)","journal-title":"ACM Comput. Surv."},{"key":"292_CR10","doi-asserted-by":"publisher","unstructured":"Fattori, A., Paleari, R., Martignoni, L., Monga, M.: Dynamic and transparent analysis of commodity production systems. In: Proceedings of the IEEE\/ACM International Conference on Automated Software Engineering, ASE \u201910, pp. 417\u2013426. ACM, New York, NY, USA (2010). doi:\n                        10.1145\/1858996.1859085","DOI":"10.1145\/1858996.1859085"},{"key":"292_CR11","unstructured":"Guarnieri, C.: Cuckoo sandbox. \n                        http:\/\/www.cuckoosandbox.org\/\n                        \n                     (2013)"},{"key":"292_CR12","doi-asserted-by":"publisher","unstructured":"Guri, M., Kedma, G., Sela, T., Carmeli, B., Rosner, A., Elovici, Y.: Noninvasive detection of anti-forensic malware. In: 8th International Conference on Malicious and Unwanted Software: \u201cThe Americas\u201d (MALWARE), pp. 1\u201310 (2013). doi:\n                        10.1109\/MALWARE.2013.6703679","DOI":"10.1109\/MALWARE.2013.6703679"},{"key":"292_CR13","unstructured":"j00ru: Defeating windows driver signature enforcement 3: the ultimate encounter. \n                        http:\/\/j00ru.vexillium.org\/?p=1455"},{"key":"292_CR14","unstructured":"Kaspersky: Equation group: questions and answers. \n                        http:\/\/securelist.com\/files\/2015\/02\/Equation_group_questions_and_answers.pdf"},{"key":"292_CR15","doi-asserted-by":"crossref","unstructured":"Kirat, D., Vigna, G., Kruegel, C.: Barebox: efficient malware analysis on bare-metal. In: Proceedings of the 27th Annual Computer Security Applications Conference, pp. 403\u2013412. ACM (2011)","DOI":"10.1145\/2076732.2076790"},{"key":"292_CR16","unstructured":"Kirat, D., Vigna, G., Kruegel, C.: Barecloud: bare-metal analysis-based evasive malware detection. In: 23rd USENIX Security Symposium (USENIX Security 14), pp. 287\u2013301. USENIX Association, San Diego, CA (2014). \n                        https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/kirat"},{"key":"292_CR17","unstructured":"Kruegel, C.: Full system emulation: achieving successful automated dynamic analysis of evasive malware. \n                        https:\/\/www.blackhat.com\/docs\/us-14\/materials\/us-14-Kruegel-Full-System-Emulation-Achieving-Successful-Automated-Dynamic-Analysis-Of-Evasive-Malware.pdf\n                        \n                     (2014)"},{"key":"292_CR18","unstructured":"Lab, K.: The regin platform\u2014nation-state ownage of gsm networks. \n                        http:\/\/securelist.com\/files\/2014\/11\/Kaspersky_Lab_whitepaper_Regin_platform_eng.pdf"},{"key":"292_CR19","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Di Federico, A., Maggi, F., Comparetti, P.M., Zanero, S.: Lines of malicious code: insights into the malicious software industry. In: Proceedings of the 28th Annual Computer Security Applications Conference. ACSAC \u201912, pp. 349\u2013358. ACM, New York, NY, USA (2012)","DOI":"10.1145\/2420950.2421001"},{"key":"292_CR20","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Kolbitsch, C., Milani\u00a0Comparetti, P.: Detecting environment-sensitive malware. In: Recent Advances in Intrusion Detection Symposium (2011)","DOI":"10.1007\/978-3-642-23644-0_18"},{"key":"292_CR21","unstructured":"Merc\u00eas, F.: Cpl malware\u2014malicious control panel items. \n                        http:\/\/www.trendmicro.com\/cloud-content\/us\/pdfs\/security-intelligence\/white-papers\/wp-cpl-malware.pdf"},{"key":"292_CR22","unstructured":"Microsoft: Device input and output control (ioctl). \n                        https:\/\/msdn.microsoft.com\/pt-br\/library\/windows\/desktop\/aa363219%28v=vs.85%29.aspx"},{"key":"292_CR23","unstructured":"Microsoft: I\/o request packets. \n                        https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/hardware\/hh439638%28v=vs.85%29.aspx"},{"key":"292_CR24","unstructured":"Microsoft: Queueuserapc function. [\n                        https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ms684954%28v=vs.85%29.aspx"},{"key":"292_CR25","unstructured":"Microsoft: Reg_notify_class enumeration. \n                        https:\/\/msdn.microsoft.com\/pt-br\/library\/windows\/hardware\/ff560950%28v=vs.85%29.aspx"},{"key":"292_CR26","unstructured":"Microsoft: Running 32-bit applications. \n                        https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa384249%28v=vs.85%29.aspx"},{"key":"292_CR27","unstructured":"Microsoft: Trojan:win32\/jorik.c. \n                        http:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/Entry.aspx?Name=Trojan:Win32\/Jorik.C"},{"key":"292_CR28","unstructured":"Microsoft: Using cplapplet. \n                        https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/cc144199%28v=vs.85%29.aspx"},{"key":"292_CR29","unstructured":"Microsoft: Win32\/wootbot. \n                        http:\/\/www.microsoft.com\/security\/portal\/threat\/encyclopedia\/entry.aspx?name=Win32%2FWootbot"},{"key":"292_CR30","unstructured":"Microsoft: CreateRemoteThread. \n                        http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/ms682437(v=vs.85).aspx\n                        \n                     (2013)"},{"key":"292_CR31","unstructured":"Microsoft: CmRegisterCallback. \n                        http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/hardware\/ff541918(v=vs.85).aspx\n                        \n                     (2014)"},{"key":"292_CR32","unstructured":"Microsoft: CmRegisterCallbackEx. \n                        http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/hardware\/ff541921(v=vs.85).aspx\n                        \n                     (2014)"},{"issue":"1","key":"292_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s13677-014-0016-2","volume":"3","author":"A More","year":"2014","unstructured":"More, A., Tapaswi, S.: Virtual machine introspection: towards bridging the semantic gap. J. Cloud Comput. 3(1), 1\u201314 (2014). doi:\n                        10.1186\/s13677-014-0016-2","journal-title":"J. Cloud Comput."},{"key":"292_CR34","doi-asserted-by":"crossref","unstructured":"Petsas, T., Voyatzis, G., Athanasopoulos, E., Polychronakis, M., Ioannidis, S.: Rage against the virtual machine: hindering dynamic analysis of android malware. In: Proceedings of the Seventh European Workshop on System Security, EuroSec \u201914, pp. 5:1\u20135:6. ACM, New York, NY, USA (2014)","DOI":"10.1145\/2592791.2592796"},{"key":"292_CR35","unstructured":"Pietrek, M.: Peering inside the pe: a tour of the win32 portable executable file format. \n                        https:\/\/msdn.microsoft.com\/en-us\/library\/ms809762.aspx"},{"key":"292_CR36","unstructured":"Reloaded, P.: Skywing. \n                        http:\/\/uninformed.org\/?v=8&a=5"},{"key":"292_CR37","unstructured":"Rienhardt, F.: Kernel-basedmonitoringonwindows(32\/64bit). \n                        http:\/\/www.bitnuts.de\/KernelBasedMonitoring.pdf\n                        \n                     (2012)"},{"key":"292_CR38","unstructured":"Rodionov, E., Matrosov, A.: The evolution of tdl: conquering x64. \n                        http:\/\/www.eset.com\/us\/resources\/white-papers\/The_Evolution_of_TDL.pdf"},{"key":"292_CR39","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1016\/j.diin.2007.06.003","volume":"4S","author":"C Seifert","year":"2007","unstructured":"Seifert, C., Steenson, R., Welch, I., Komisarczuk, P., Endicott-Popovsky, B.: Capture\u2014a behavioral analysis tool for applications and documents. Digit. Investig. 4S, 23\u201330 (2007)","journal-title":"Digit. Investig."},{"key":"292_CR40","volume-title":"Practical Malware Analysis: The Hands-on Guide to Dissecting Malicious Software","author":"M Sikorski","year":"2012","unstructured":"Sikorski, M., Honig, A.: Practical Malware Analysis: The Hands-on Guide to Dissecting Malicious Software. No Starch Press, San Francisco (2012)"},{"key":"292_CR41","unstructured":"skape, Skywing: Bypassing patchguard on windows x64. \n                        http:\/\/uninformed.org\/index.cgi?v=3&a=3"},{"key":"292_CR42","unstructured":"Skywing: Subverting patchguard version 2. \n                        http:\/\/www.uninformed.org\/?a=1&t=txt&v=6"},{"key":"292_CR43","doi-asserted-by":"crossref","unstructured":"Thomas, S., Sherly, K., Dija, S.: Extraction of memory forensic artifacts from windows 7 ram image. In: 2013 IEEE Conference on Information and Communication Technologies (ICT), pp. 937\u2013942. IEEE (2013)","DOI":"10.1109\/CICT.2013.6558230"},{"key":"292_CR44","unstructured":"TrendMicro: Darkkomet. \n                        http:\/\/www.trendmicro.com\/vinfo\/us\/threat-encyclopedia\/malware\/DARKCOMET"},{"key":"292_CR45","unstructured":"TrendMicro: Tspy64_zbot.aanp. \n                        http:\/\/about-threats.trendmicro.com\/Malware.aspx?language=au&name=TSPY64_ZBOT.AANP"},{"key":"292_CR46","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MSP.2007.45","volume":"5","author":"C Willems","year":"2007","unstructured":"Willems, C., Holz, T., Freiling, F.: Toward automated dynamic malware analysis using cwsandbox. IEEE Secur. Priv. 5, 32\u201339 (2007)","journal-title":"IEEE Secur. Priv."},{"key":"292_CR47","unstructured":"Willems, C., Hund, R., Holz, T.: Cxpinspector: Hypervisor-based, hardware-assisted system monitoring. Tech. Rep. TR-HGI-2012-002, HGI, Ruhr-Universitat Bochum (2012)"}],"container-title":["Journal of Computer Virology and Hacking Techniques"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s11416-017-0292-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0292-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s11416-017-0292-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2018,2,22]],"date-time":"2018-02-22T23:48:37Z","timestamp":1519343317000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s11416-017-0292-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,27]]},"references-count":47,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2018,2]]}},"alternative-id":["292"],"URL":"https:\/\/doi.org\/10.1007\/s11416-017-0292-8","relation":{},"ISSN":["2263-8733"],"issn-type":[{"value":"2263-8733","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,27]]}}}