Flag: Tornado! Hurricane!


Packer Name Packer Author Classification Analysis By Last Updated
nPack v1.1 NEOx Compressor saphex January 24 2008
Allocation Anti-Debug Anti-Disassembly Section Name Sample
VirtualAlloc no no [configurable, default = .npack] N/A
Notes
Nothing special, just a simple compressor.

Transfer Command
00000000 C7 05 ?? ?? ?? ?? 01 00 00 00   mov     ds:value, 1
0000000A 01 05 ?? ?? ?? ??               add     ds:value, eax
00000010 FF 35 ?? ?? ?? ??               push    ds:value
00000015 C3                              retn
Entry Point Signature
00000000 83 3D ?? ?? ?? ?? 00            cmp     ds:value, 0
00000007 75 05                           jnz     short 0000000D
00000009 E9 01 00 00 00                  jmp     0000000E
0000000D C3                              retn
0000000E E8 ?? ?? ?? ??                  call    value
00000013 E8 ?? ?? ?? ??                  call    value
Known Unpackers
A simple way to find the original entry point, is to add a
breakpoint in the transfer command (ret instruction), since
the transfer command is in the packer stub beginning. Just
single step it and you will be at the original entry point.

There are 29,954 total registered users.


Recently Created Topics
Disassembling Motoro...
Jun/13
ida plugin writing f...
Jun/02
New version of RE-Go...
May/29
Decompiling raw bina...
May/22
Incorrect bitness wh...
May/20
PaiMei stalker modul...
May/19
Attach to program us...
May/13
IDA PRO how to make ...
May/12
FACT: OpenRCE is dead.
May/08
Int 3 anti debug?
May/05


Recent Forum Posts
Good Binary Code Pro...
alton
Int 3 anti debug?
SteveIRQL
Attach to program us...
SteveIRQL
Ollydbg 2.0 - Plugin...
openrce...
IDA PRO how to make ...
codeinject
FACT: OpenRCE is dead.
codeinject
IDA Resource Viewer ...
r2x64
FACT: OpenRCE is dead.
djnemo
FACT: OpenRCE is dead.
codeinject
FACT: OpenRCE is dead.
pedram


Recent Blog Entries
lowpriority
Apr/13
OllyMigrate Plugin for Olly...

everdox
Mar/08
2 anti-trace mechanisms spe...

everdox
Mar/07
Advanced debugging techniques

everdox
Mar/06
Branch tracing and LBR acce...

everdox
Mar/05
Using pre-paged in virtual ...

More ...


Recent Blog Comments
capadleman on:
Jun/19
Using NtCreateThreadEx for ...

newlulu on:
Jun/10
Branch tracing and LBR acce...

newlulu on:
Jun/10
Advanced debugging techniques

newlulu on:
Jun/10
2 anti-trace mechanisms spe...

newlulu on:
Jun/10
OllyMigrate Plugin for Olly...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit