Kayaker
April 19th, 2011, 22:08
Nothing really "new" but a good article on methods of capturing API strings in malware and their significance. A handy table at the end lists common API's as used in a malware context.
http://www.sans.org/reading_room/whitepapers/malicious/malcode-context-api-abuse_33649
http://www.sans.org/reading_room/whitepapers/malicious/malcode-context-api-abuse_33649