原创: packman 0.0.0.1快速脱壳
Author Homepage:
764K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4m8S2j5$3E0E0j5h3&6Q4x3X3g2U0K9X3u0Q4x3X3g2F1k6i4c8Q4x3V1j5`.
Download:
75cK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3q4K6L8h3u0#2j5X3u0S2i4K6u0W2k6Y4u0W2k6i4m8J5L8$3S2G2M7%4c8Q4x3X3g2U0L8$3#2Q4x3V1k6V1L8%4N6F1L8r3!0S2k6q4)9J5c8Y4m8S2j5$3E0E0j5h3&6Q4x3X3b7H3i4K6u0W2x3q4)9J5k6e0m8Q4x3X3f1I4i4K6u0W2P5X3W2H3
工具: ollydbg,ollydump,imprec
作者: peaceclub[5261314@sohu.com]
描述: packman 0.0.0.1 :An average compression tool, with many potential. UPX, Mew, Upack packed files are smaller. But the tool has a small and nice GUI.
脱壳过程:
1、ollydbg载入Packman.exe
2、停在这里
00410F84 > 60 PUSHAD 'oep 00410F85 E8 00000000 CALL Packman.00410F8A 00410F8A 58 POP EAX 00410F8B 8DA8 9AFEFFFF LEA EBP,DWORD PTR DS:[EAX-166] 00410F91 8D98 76F0FEFF LEA EBX,DWORD PTR DS:[EAX+FFFEF076] 00410F97 8DB0 74010000 LEA ESI,DWORD PTR DS:[EAX+174] 00410F9D 8D4E F6 LEA ECX,DWORD PTR DS:[ESI-A] 00410FA0 48 DEC EAX 00410FA1 C640 FB E9 MOV BYTE PTR DS:[EAX-5],0E9 00410FA5 8D93 7A760000 LEA EDX,DWORD PTR DS:[EBX+767A] 00410FAB 2BD0 SUB EDX,EAX
3、F8
4、把光标移动到00410f84: pushad处,f4,f8
5、dump & imprec
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课