Flag: Tornado! Hurricane!


Packer Name Packer Author Classification Analysis By Last Updated
AntiDeb unknown Crypter quig July 1 2005
Allocation Anti-Debug Anti-Disassembly Section Name Sample
peheader yes no .text and blank n/a
Notes
Last Update: now

small packer ~300bytes, ep just before import table, jmps over import data to rest of code, uses isDebuggerPresent twice, more or less straight line function, with one seh call , mucks with peb so cant dump with lordpe, use ollydmp

Transfer Command
push oep ;@ far bottom of code of main function 
ret      ;  has to self decrypt first..

  
Entry Point Signature
0040C000 > EB 58            JMP SHORT 0040C05A
0040C002   87DB             XCHG EBX,EBX
0040C004   39C0             CMP EAX,EAX
0040C006   0000             ADD BYTE PTR DS:[EAX],AL
0040C008   0000             ADD BYTE PTR DS:[EAX],AL
0040C00A   0000             ADD BYTE PTR DS:[EAX],AL
0040C00C   0000             ADD BYTE PTR DS:[EAX],AL
0040C00E   0000             ADD BYTE PTR DS:[EAX],AL
0040C010   2C C0            SUB AL,0C0
Known Unpackers

There are 31,054 total registered users.


Recently Created Topics
Ultimate Hacking Cha...
Jun/21
CreateMutex
May/31
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Immunity Debugger Re...
Aug/03


Recent Forum Posts
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n
OOP_RE tool available?
van7hu
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack


Recent Blog Entries
crystalwade
Jul/20
test

nieo
Mar/22
Android Application Reversing

halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit