flare-floss
flare-floss copied to clipboard
Heuristic to identify calls to LoadLibrary and GetProcAddress
Might be a good way to catch more (inlined) decoding routines. Sample: 02b2d905a72c4bb2abfc278b8ca7f722.
capa has an implementation here: https://github.com/fireeye/capa/blob/master/capa/features/extractors/viv/indirect_calls.py