Flag: Tornado! Hurricane!


Packer Name Packer Author Classification Analysis By Last Updated
EZIP 1.0 Jonathan Clark Compressor quig June 15 2005
Allocation Anti-Debug Anti-Disassembly Section Name Sample
VirtualAlloc() + PE Header no no original * 2 N/A
Notes
More or less straight line function with OEP at the end just before a RET.

Leaves one API import per DLL in-header, loads the rest as pointers.

Transfer Command
004082DC  /> 55             PUSH EBP
004082DD  |. 8BEC           MOV EBP,ESP

GlobalAlloc
getmodulefilename
createfilea (openself)
set file pointer
VirtualAlloc
VirtualProtect
DecompLoop
-Alloc/Protect
end decomploop
closehandle 

00408662  |. 59             POP ECX
00408663  |. 59             POP ECX
00408664  |. 8B85 2CFCFFFF  MOV EAX,DWORD PTR SS:[EBP-3D4]
0040866A  |. 8B40 10        MOV EAX,DWORD PTR DS:[EAX+10]
0040866D  |. 8B8D 2CFCFFFF  MOV ECX,DWORD PTR SS:[EBP-3D4]
00408673  |. 0341 1C        ADD EAX,DWORD PTR DS:[ECX+1C]
00408676  |. 8985 38FCFFFF  MOV DWORD PTR SS:[EBP-3C8],EAX
0040867C  |. 8B85 38FCFFFF  MOV EAX,DWORD PTR SS:[EBP-3C8]
00408682  |. 5F             POP EDI
00408683  |. 5E             POP ESI
00408684  |. 5B             POP EBX
00408685  |. 8BE5           MOV ESP,EBP
00408687  |. 5D             POP EBP
00408688  |. FFE0           JMP EAX               ;----------OEP
0040868A  |> 5F             POP EDI
0040868B  |. 5E             POP ESI
0040868C  |. 5B             POP EBX
0040868D  |. C9             LEAVE
0040868E  . C3             RETN

Entry Point Signature
004050BE > $ E9 19320000    JMP 004082DC                           
004050C3   . E9 7C2A0000    JMP 00407B44                             
004050C8   $ E9 19240000    JMP 004074E6                           
004050CD   $ E9 FF230000    JMP 004074D1                           
004050D2   . E9 1E2E0000    JMP 00407EF5                           
004050D7   $ E9 882E0000    JMP 00407F64                             
004050DC   $ E9 2C250000    JMP 0040760D                     
004050E1   $ E9 AE150000    JMP 00406694           
004050E6   $ E9 772B0000    JMP 00407C62              
004050EB   $ E9 87020000    JMP 00405377             
004050F0   $ E9 702E0000    JMP 00407F65                
004050F5     CC             INT3
004050F6     CC             INT3
004050F7     CC             INT3
004050F8     CC             INT3
004050F9     CC             INT3
004050FA     CC             INT3
004050FB     CC             INT3
004050FC     CC             INT3
004050FD     CC             INT3
Known Unpackers
// Script for OllyScript plugin by SHaG - http://ollyscript.apsvans.com
//by DarK_m00n | CiM 
var a
findop eip, #FFE0#
go $RESULT
cmt eip, "Jmp To OEP"
sto
an eip
MSGYN "Do u wanna to Unpack it ?"
cmp $RESULT,0
je he_refuze
mov a,"c:\D_file_unpacked.exe"
dpe a,eip
MSG a
he_refuze:
ret
Active in Last 5 Minutes
st1

There are 30,637 total registered users.


Recently Created Topics
Question about debbu...
Apr/16
IDA PRO Struct Point...
Apr/15
problems with pseudo...
Apr/04
Problem with ollydbg
Mar/22
Should binaries be n...
Mar/22
Ida pro on infineon ...
Mar/10
need help about an D...
Feb/25
Stop a VB6 Applicati...
Feb/13
Add one new segment,...
Jan/23
64bit calc.exe Stack...
Jan/19


Recent Forum Posts
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack
looking for a softwa...
raxen
Documenting reversed...
raxen
.orpc section what's...
mbin
Pydbg load() issue
phreak
Pydbg load() issue
netw0rm
How would you interp...
mbin
Pydbg load() issue
phreak


Recent Blog Entries
valeriegraey
Apr/23
KeraPlex Bio Review - Actua...

xiaofeng01
Apr/23
At Drug Rehabs in Autentic ...

xiaofeng01
Apr/23
Harry Vardon, British Golfe...

Harvelcrown
Apr/22
Stay Young and Beautiful

oleavr
Apr/17
frida.re 1.2.0 is out, with...

More ...


Recent Blog Comments
pedram on:
Dec/21
frida.github.io: scriptable...

NeOXQuiCk on:
Nov/26
DONGLE

maharlee on:
Nov/21
Cheap Nike Shoes NZ,Nike Sh...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

newlulu on:
Jun/10
Branch tracing and LBR acce...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit