Flag: Tornado! Hurricane!

Error: Authentication required to access requested resource.


Packer Name Packer Author Classification Analysis By Last Updated
UPX Crypt archphase (NWC) UPX Modifier quig May 1 2005
Allocation Anti-Debug Anti-Disassembly Section Name Sample
PE Header (UPX) yes yes .nwc (default) N/A
Notes
modified upx packed exe

adds new section with variable section name to exe for decode stub

uses a variable passkey for encryption

offsets align with sample

Transfer Command
jmp esi
Entry Point Signature
00407000 > BF 30544000      MOV EDI,in.00405430       ;this block is entire decode loop
00407005   81FF D0554000    CMP EDI,in.004055D0
0040700B   74 10            JE SHORT in.0040701D
0040700D   812F 0B000000    SUB DWORD PTR DS:[EDI],0B
00407013   83C7 04          ADD EDI,4
00407016   BB 05704000      MOV EBX,in.00407005
0040701B   FFE3             JMP EBX
0040701D   BE 30544000      MOV ESI,in.00405430
00407022  -FFE6             JMP ESI                   ;esi=405430  end of decode loop                         

00405430   ? 60             PUSHAD               ;start of regular upx stub
00405431   ? BE 00504000    MOV ESI,in.00405000
00405436   . 8DBE 00C0FFFF  LEA EDI,DWORD PTR DS:[ESI+FFFFC000]
0040543C   . 57             PUSH EDI
0040543D   . 83CD FF        OR EBP,FFFFFFFF
00405440   . EB 10          JMP SHORT in.00405452
00405442     90             NOP
00405443     90             NOP
00405444     90             NOP
00405445     90             NOP
00405446     90             NOP
00405447     90             NOP
Known Unpackers
Active in Last 5 Minutes
dvvord

There are 16,646 total registered users.


Recently Created Topics
SSL keyfindert plugi...
Mar/15
ApiHooks.com down
Mar/15
how to crate a PATC...
Mar/10
wsnpoem audio.dll
Mar/09
suggestions - RE tra...
Mar/09
Requesting Suggestio...
Mar/06
Force enable debug p...
Mar/05
upgrading new image ...
Mar/03
upgrading new image ...
Mar/03
upgrading new image ...
Mar/03


Recent Forum Posts
suggestions - RE tra...
enm16
wsnpoem audio.dll
zhane
suggestions - RE tra...
Silkut
how to crate a PATC...
Silkut
suggestions - RE tra...
RolfRolles
wsnpoem audio.dll
debbie
Requesting Suggestio...
secursig
Requesting Suggestio...
phn1x
how to get executabl...
RabidCi...
how to get executabl...
RabidCi...


Recent Blog Entries
RolfRolles
Mar/08
Compiler Optimizations for ...

ReWolf
Mar/04
When memory management goes...

thesprawler
Feb/20
log1949.txt -- Wondering ho...

thesprawler
Feb/20
log1949.log -- created on C...

thesprawler
Feb/17
Trying to reverse the firmw...

More ...


Recent Blog Comments
Boken on:
Mar/12
Compiler Optimizations for ...

wildinto on:
Mar/10
Compiler Optimizations for ...

Orr on:
Mar/10
Compiler Optimizations for ...

bughoho on:
Mar/09
Compiler Optimizations for ...

cliffwolf on:
Mar/08
Compiler Optimizations for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit