Flag: Tornado! Hurricane!


Packer Name Packer Author Classification Analysis By Last Updated
EZIP 1.0 Jonathan Clark Compressor quig June 15 2005
Allocation Anti-Debug Anti-Disassembly Section Name Sample
VirtualAlloc() + PE Header no no original * 2 N/A
Notes
More or less straight line function with OEP at the end just before a RET.

Leaves one API import per DLL in-header, loads the rest as pointers.

Transfer Command
004082DC  /> 55             PUSH EBP
004082DD  |. 8BEC           MOV EBP,ESP

GlobalAlloc
getmodulefilename
createfilea (openself)
set file pointer
VirtualAlloc
VirtualProtect
DecompLoop
-Alloc/Protect
end decomploop
closehandle 

00408662  |. 59             POP ECX
00408663  |. 59             POP ECX
00408664  |. 8B85 2CFCFFFF  MOV EAX,DWORD PTR SS:[EBP-3D4]
0040866A  |. 8B40 10        MOV EAX,DWORD PTR DS:[EAX+10]
0040866D  |. 8B8D 2CFCFFFF  MOV ECX,DWORD PTR SS:[EBP-3D4]
00408673  |. 0341 1C        ADD EAX,DWORD PTR DS:[ECX+1C]
00408676  |. 8985 38FCFFFF  MOV DWORD PTR SS:[EBP-3C8],EAX
0040867C  |. 8B85 38FCFFFF  MOV EAX,DWORD PTR SS:[EBP-3C8]
00408682  |. 5F             POP EDI
00408683  |. 5E             POP ESI
00408684  |. 5B             POP EBX
00408685  |. 8BE5           MOV ESP,EBP
00408687  |. 5D             POP EBP
00408688  |. FFE0           JMP EAX               ;----------OEP
0040868A  |> 5F             POP EDI
0040868B  |. 5E             POP ESI
0040868C  |. 5B             POP EBX
0040868D  |. C9             LEAVE
0040868E  . C3             RETN

Entry Point Signature
004050BE > $ E9 19320000    JMP 004082DC                           
004050C3   . E9 7C2A0000    JMP 00407B44                             
004050C8   $ E9 19240000    JMP 004074E6                           
004050CD   $ E9 FF230000    JMP 004074D1                           
004050D2   . E9 1E2E0000    JMP 00407EF5                           
004050D7   $ E9 882E0000    JMP 00407F64                             
004050DC   $ E9 2C250000    JMP 0040760D                     
004050E1   $ E9 AE150000    JMP 00406694           
004050E6   $ E9 772B0000    JMP 00407C62              
004050EB   $ E9 87020000    JMP 00405377             
004050F0   $ E9 702E0000    JMP 00407F65                
004050F5     CC             INT3
004050F6     CC             INT3
004050F7     CC             INT3
004050F8     CC             INT3
004050F9     CC             INT3
004050FA     CC             INT3
004050FB     CC             INT3
004050FC     CC             INT3
004050FD     CC             INT3
Known Unpackers
// Script for OllyScript plugin by SHaG - http://ollyscript.apsvans.com
//by DarK_m00n | CiM 
var a
findop eip, #FFE0#
go $RESULT
cmt eip, "Jmp To OEP"
sto
an eip
MSGYN "Do u wanna to Unpack it ?"
cmp $RESULT,0
je he_refuze
mov a,"c:\D_file_unpacked.exe"
dpe a,eip
MSG a
he_refuze:
ret
Active in Last 5 Minutes
timtoady

There are 21,677 total registered users.


Recently Created Topics
PyEmu error when cal...
Sep/02
Restore Themida/Winl...
Sep/02
Anti-olly technique
Aug/30
RAR Password
Aug/29
Heap protection on W...
Aug/23
Why Inline asm in C+...
Aug/20
Bypassing OllyAdvance
Aug/17
Error in logic for g...
Aug/17
Has anyone seen this...
Aug/17
ARM Executable - Pat...
Aug/16


Recent Forum Posts
reverse engineering ...
raiden56
pydbg, memory breakp...
Researc...
RAR Password
Ineedhelp
RAR Password
cod
Heap protection on W...
voila
Heap protection on W...
j00ru
Heap protection on W...
voila
Heap protection on W...
j00ru
Heap protection on W...
psylocn
Why Inline asm in C+...
ronnie2...


Recent Blog Entries
meshmesh
Sep/01
Is it legal??

waleedassar
Aug/30
Anti-olly technique

QvasiModo
Aug/24
WinAppDbg 1.4 is out!

artemblagodarenko
Aug/18
Dataflow-0.2.0 released. Ne...

grzonu
Aug/17
Bypassing OllyAdvanced

More ...


Recent Blog Comments
tosanjay on:
Sep/02
PyEmu 0.0.2

GynvaelColdwind on:
Sep/01
Is it legal??

PeterFerrie on:
Aug/31
Anti-olly technique

dennis on:
Aug/26
Dr. Gadget IDAPython plugin

halsten on:
Aug/19
Dataflow-0.2.0 released. Ne...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit