Included in this archive is a private rootkit found in the wild that uses libcall hijacking. A detailed research analysis of how it functions has been created and is in the ncom.txt file.
You can download it from the following link: https://packetstormsecurity.com/files/download/99782/ncom.tar.gz
Source: https://packetstormsecurity.com/files/99782/Ncom-Libcall-Hijacking-Rootkit.html