📚 OpenRCE is preserved as a read-only archive. Launched at RECon Montreal in 2005. Registration and posting are disabled.








Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  unusual entry point

Topic created on: January 8, 2009 19:39 CST by mugg .

Does anyone know the packer associated with an entry point like this one? It's shown up in a few families of current malware:
.text:004012C5 start           proc near
.text:004012C5
.text:004012C5 var_14          = dword ptr -14h
.text:004012C5
.text:004012C5                 push    ebp
.text:004012C6                 mov     ebp, esp
.text:004012C8                 push    0FFFFFFFFh
.text:004012CA                 push    0
.text:004012CF                 push    0
.text:004012D4                 mov     eax, large fs:0
.text:004012DA                 push    eax
.text:004012DB                 mov     large fs:0, esp
.text:004012E2                 push    0EB527209h
.text:004012E7                 push    ebx
.text:004012E8                 push    2BEF53D4h
.text:004012ED                 push    2B0AD23h
.text:004012F2                 call    nullsub_1
.text:004012F7                 push    0ACCEB026h
.text:004012FC                 call    sub_401248
.text:00401301                 push    ecx
.text:00401302                 call    sub_401273
.text:00401307                 push    90D3094Dh
.text:0040130C                 push    95601A48h
.text:00401311                 push    eax
.text:00401312                 push    edx
.text:00401313                 call    sub_40123B

  Kleissner     January 13, 2009 15:32.49 CST
msvcrt/msvcrXX code?

what is there unusual? first few lines SEH exception handler registration...

Kleissner

  neoxfx     January 13, 2009 22:36.16 CST
@Kleissner: dude, how often do you see exception handler set to address zero? :-)

  Kleissner     January 14, 2009 00:17.27 CST
hum yeah maybe your code expects to be corrected by some malicious loader?
if you give me details about the virus (what family or what sample etc.) then I can take a look... out of context its mostly useless to analyze such a thing...

  mugg     January 14, 2009 12:12.34 CST
thanks for the response, already taken care of...neoxfx has some great insight  :)

Note: Registration is required to post to the forums.

There are 31,328 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Question about memor...
Dec/12


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit