semantic-jargon-export-obfuscation
PE export table flooded with a mix of semantically-plausible, real-world API names (typically from legitimate open-source or commercial libraries) and random alphanumeric noise names. The legitimate-looking exports serve as camouflage during superficial triage, while the noise names poison string-based clustering and automated detection.
Observed Manifestation
Sample 9a69ad1b (2.5 MB PE32+ DLL, .NET 9 Native AOT) contains 163 exports:
- 39 real Microsoft Edge / Chromium ELF / Crashpad export names (
PwaHelperImpl,SignalChromeElf,EdgeGetElfCommandLine,GetCrashpadDatabasePath_ExportThunk, etc.) - 124 noise names like
03Z1V9eKQfj7aZO4lZ5BknYZe,08MBh2GSIL8VIQk7kZGA0
All exports resolve to tiny stubs in .text. The real names are mangled C++ symbols with full namespace and parameter types, giving them high semantic credibility during manual review. ^[raw/analyses/9a69ad1b.../report.md]
Detection
- Compare export names against known benign software catalogues; flag binaries whose export table is a superset of a real product's exports plus noise.
- Check export-to-code-size ratio: 163 exports in a 357-byte entry-point stub is anomalous.
- Cross-reference
OriginalFilename/InternalNameagainst the claimed product identity in exports.
Related
- version-info-masquerade — frequently paired with export-table masquerade
- legitimate-library-masquerade — broader concept of cloning benign identities
- unclassified-dotnet-native-aot-loader — family where this technique was first observed