为何同款恶意软件在Win7与Win10分别从不同DLL导出CreateProcessInternalW?
Why Malware Exports
CreateProcessInternalW from Different DLLs on Windows 7 vs Windows 10 Great question! This boils down to two core pieces: Microsoft's restructuring of Windows system libraries over time, and malware authors' deliberate efforts to slip past security defenses. Let's break it down clearly:
1. How Windows System DLLs Changed
- On Windows 7 and older versions, the
CreateProcessInternalWfunction was directly implemented and exported fromkernel32.dll—this was the standard home for core Windows API functions back then. - Starting with Windows 8 (and carried over to Windows 10+), Microsoft moved many low-level API implementations to
KernelBase.dll. The version ofCreateProcessInternalWinkernel32.dllnow acts as nothing more than a forwarder (a tiny piece of code that jumps straight to the real implementation inKernelBase.dll).
In short: the actual code behind the function shifted from kernel32.dll to KernelBase.dll between these OS generations.
2. Why Malware Targets the "Real" Implementation
Malware authors intentionally target the DLL where the function's actual code lives for key evasion reasons:
- Bypass user-mode hooks: Many security tools (like endpoint detection systems) hook API functions in
kernel32.dllto monitor suspicious activity (like hidden process creation). By calling the function directly fromKernelBase.dll, malware skips these hooks entirely, flying under the detection radar. - Hide from static analysis: Static scanning tools often flag calls to well-known
kernel32.dllexports as potential red flags. UsingKernelBase.dllmakes the malicious behavior less obvious during initial automated scans. - Avoid compatibility layer interference:
kernel32.dllsometimes includes compatibility logic for older applications. By skipping this layer, malware ensures its process creation logic runs exactly as intended, with no unexpected modifications.
内容的提问来源于stack exchange,提问作者Limpid.Security
相关产品推荐
相关产品推荐

