typetechniqueconfidencemediumcreated2026-08-07updated2026-08-07evasiondefense-evasionanti-analysispe-export-table

semantic-jargon-export-obfuscation

PE export table flooded with a mix of semantically-plausible, real-world API names (typically from legitimate open-source or commercial libraries) and random alphanumeric noise names. The legitimate-looking exports serve as camouflage during superficial triage, while the noise names poison string-based clustering and automated detection.

Observed Manifestation

Sample 9a69ad1b (2.5 MB PE32+ DLL, .NET 9 Native AOT) contains 163 exports:

  • 39 real Microsoft Edge / Chromium ELF / Crashpad export names (PwaHelperImpl, SignalChromeElf, EdgeGetElfCommandLine, GetCrashpadDatabasePath_ExportThunk, etc.)
  • 124 noise names like 03Z1V9eKQfj7aZO4lZ5BknYZe, 08MBh2GSIL8VIQk7kZGA0

All exports resolve to tiny stubs in .text. The real names are mangled C++ symbols with full namespace and parameter types, giving them high semantic credibility during manual review. ^[raw/analyses/9a69ad1b.../report.md]

Detection

  • Compare export names against known benign software catalogues; flag binaries whose export table is a superset of a real product's exports plus noise.
  • Check export-to-code-size ratio: 163 exports in a 357-byte entry-point stub is anomalous.
  • Cross-reference OriginalFilename / InternalName against the claimed product identity in exports.

Related