hasherezade / malware_training_vol1

Materials for Windows Malware Analysis training (volume 1)
1.94k stars 186 forks source link

Vol1-Mod1.4WoW64-Slide3 - Emulator vs Subsystem #14

Open BlueSkeye opened 3 years ago

BlueSkeye commented 3 years ago

AFAIU WoW64 is an emulator not a subsystem.

Microsoft itself defines WoW64 as an emulator : https://docs.microsoft.com/en-us/windows/win32/winprog64/wow64-implementation-details ... while it advertises WSL as a subsystem : https://docs.microsoft.com/en-us/windows/wsl/

hasherezade commented 3 years ago

AFAIU WoW64 is an emulator not a subsystem.

Microsoft itself defines WoW64 as an emulator : https://docs.microsoft.com/en-us/windows/win32/winprog64/wow64-implementation-details

Yes, and this emulator is also known as subsystem.

"In computing on Microsoft platforms, WoW64 (Windows 32-bit on Windows 64-bit) is a subsystem of the Windows operating system capable of running 32-bit applications on 64-bit Windows." - via Wikipedia

"Dive deep into the WOW64 subsystem and see how malware abuses Heavens Gate" - FireEye's tweet

Just Google for more if you need.