Flag: Tornado! Hurricane!


Packer Name Packer Author Classification Analysis By Last Updated
nPack v1.1 NEOx Compressor saphex January 24 2008
Allocation Anti-Debug Anti-Disassembly Section Name Sample
VirtualAlloc no no [configurable, default = .npack] N/A
Notes
Nothing special, just a simple compressor.

Transfer Command
00000000 C7 05 ?? ?? ?? ?? 01 00 00 00   mov     ds:value, 1
0000000A 01 05 ?? ?? ?? ??               add     ds:value, eax
00000010 FF 35 ?? ?? ?? ??               push    ds:value
00000015 C3                              retn
Entry Point Signature
00000000 83 3D ?? ?? ?? ?? 00            cmp     ds:value, 0
00000007 75 05                           jnz     short 0000000D
00000009 E9 01 00 00 00                  jmp     0000000E
0000000D C3                              retn
0000000E E8 ?? ?? ?? ??                  call    value
00000013 E8 ?? ?? ?? ??                  call    value
Known Unpackers
A simple way to find the original entry point, is to add a
breakpoint in the transfer command (ret instruction), since
the transfer command is in the packer stub beginning. Just
single step it and you will be at the original entry point.

There are 31,313 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit