Research Article

Toward Detecting Malware Based on Process-Aware Behaviors

Table 2

The feature matrix of LoadLibraryExW for two samples. For clarity, S1 is abbreviated to Sample1, and S2 to Sample2.

 user32.dllgdi32.dllws2_32.dllLabel

S12101
S20010