{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T16:07:19Z","timestamp":1774195639229,"version":"3.50.1"},"reference-count":19,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010,10]]},"DOI":"10.1109\/malware.2010.5665788","type":"proceedings-article","created":{"date-parts":[[2010,12,21]],"date-time":"2010-12-21T18:39:39Z","timestamp":1292956779000},"page":"91-97","source":"Crossref","is-referenced-by-count":18,"title":["Multi-stage delivery of malware"],"prefix":"10.1109","author":[{"given":"Marco","family":"Ramilli","sequence":"first","affiliation":[]},{"given":"Matt","family":"Bishop","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","first-page":"8","article-title":"Dichotomy: Double trouble","author":"kaspersky","year":"1994","journal-title":"Virus Bulletin"},{"key":"ref11","first-page":"8","article-title":"RMNS&#x2014;the perfect couple","author":"kaspersky","year":"1995","journal-title":"Virus Bulletin"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)00012-W"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/1179576.1179578"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2003.1174909"},{"key":"ref15","author":"ptacek","year":"1998","journal-title":"Insertion evasion and denial of service Eluding network intrusion detection"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"ref17","first-page":"17","article-title":"An automatic anti-anti-vmware technique applicable for multi-stage packed malware","author":"sun","year":"1984","journal-title":"3rd International Conference on Malicious and Unwanted Software (MALWARE)"},{"key":"ref18","author":"szor","year":"2005","journal-title":"The Art of Computer Virus Research and Defense"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/366173.366187"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/1413140.1413151"},{"key":"ref3","article-title":"Advances in Information Security","author":"aycock","year":"2006","journal-title":"Computer Ciruses and Malware"},{"key":"ref6","first-page":"240","article-title":"Computer viruses: Theory and experiments","author":"cohen","year":"1984","journal-title":"Proceedings of the 7th DoD\/NBS Computer Security Conference"},{"key":"ref5","author":"cluley","year":"0","journal-title":"Av-test org's malware count exceeds 22 million"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICPPW.2002.1039705"},{"key":"ref7","author":"cui","year":"2006","journal-title":"GQ Realizing a system to catch worms in a quarter million places"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/1179542.1179554"},{"key":"ref1","year":"1999","journal-title":"Melissa macro virus CERT Advisory CA-1999&#x2013;04 CERT"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1989.36307"}],"event":{"name":"2010 5th International Conference on Malicious and Unwanted Software (MALWARE)","location":"Nancy, France","start":{"date-parts":[[2010,10,19]]},"end":{"date-parts":[[2010,10,20]]}},"container-title":["2010 5th International Conference on Malicious and Unwanted Software"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/5655114\/5665785\/05665788.pdf?arnumber=5665788","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2017,3,21]],"date-time":"2017-03-21T06:51:28Z","timestamp":1490079088000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/5665788\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010,10]]},"references-count":19,"URL":"https:\/\/doi.org\/10.1109\/malware.2010.5665788","relation":{},"subject":[],"published":{"date-parts":[[2010,10]]}}}