1,BP GetVersion
77E5D142 > 64:A1 18000000 MOV EAX,DWORD PTR FS:[18]
77E5D148 8B48 30 MOV ECX,DWORD PTR DS:[EAX+30]
77E5D14B 8B81 B0000000 MOV EAX,DWORD PTR DS:[ECX+B0]
77E5D151 0FB791 AC000000 MOVZX EDX,WORD PTR DS:[ECX+AC]
77E5D158 83F0 FE XOR EAX,FFFFFFFE
77E5D15B C1E0 0E SHL EAX,0E
77E5D15E 0BC2 OR EAX,EDX
77E5D160 C1E0 08 SHL EAX,8
77E5D163 0B81 A8000000 OR EAX,DWORD PTR DS:[ECX+A8]
77E5D169 C1E0 08 SHL EAX,8
77E5D16C 0B81 A4000000 OR EAX,DWORD PTR DS:[ECX+A4]
77E5D172 C3 RETN
------>
2,
0042BABF FF70 04 PUSH DWORD PTR DS:[EAX+4]
0042BAC2 FF55 E8 CALL DWORD PTR SS:[EBP-18]
0042BAC5 C3 RETN
0042BAC6 58 POP EAX
0042BAC7 8945 94 MOV DWORD PTR SS:[EBP-6C],EAX
0042BACA FF55 E4 CALL DWORD PTR SS:[EBP-1C]--->GetVersion
0042BACD C1E8 1F SHR EAX,1F
0042BAD0 8945 FC MOV DWORD PTR SS:[EBP-4],EAX
0042BAD3 FF55 E0 CALL DWORD PTR SS:[EBP-20]
--->GetCommandLineA
0042BAD6 8945 E0 MOV DWORD PTR SS:[EBP-20],EAX
0042BAD9 8D85 D4FEFFFF LEA EAX,DWORD PTR SS:[EBP-12C]
0042BADF 50 PUSH EAX
0042BAE0 FF95 24FFFFFF CALL DWORD PTR SS:[EBP-DC]
0042BAE6 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
3,往上看,
0042B881 ^\75 F4 JNZ SHORT 样本测试.0042B877
0042B883 61 POPAD
OEP:[2B884] DUMP it <<<<++++++++++++++++++++
0042B884 55 PUSH EBP
0042B885 8BEC MOV EBP,ESP
0042B887 81EC 2C010000 SUB ESP,12C
0042B88D 53 PUSH EBX
0042B88E 56 PUSH ESI
0042B88F 57 PUSH EDI
0042B890 C785 40FFFFFF 9>MOV DWORD PTR SS:[EBP-C0],16D559C
0042B89A C785 44FFFFFF 9>MOV DWORD PTR SS:[EBP-BC],16D5590
0042B8A4 C785 48FFFFFF 9>MOV DWORD PTR SS:[EBP-B8],16D5594
0042B8AE C785 4CFFFFFF 8>MOV DWORD PTR SS:[EBP-B4],16D5588
0042B8B8 C785 50FFFFFF 8>MOV DWORD PTR SS:[EBP-B0],16D558C
0042B8C2 C785 54FFFFFF 8>MOV DWORD PTR SS:[EBP-AC],16D5580
0042B8CC C785 58FFFFFF 8>MOV DWORD PTR SS:[EBP-A8],16D5584
0042B8D6 C785 5CFFFFFF B>MOV DWORD PTR SS:[EBP-A4],16D55B8
0042B8E0 C785 60FFFFFF B>MOV DWORD PTR SS:[EBP-A0],16D55BC
0042B8EA C785 64FFFFFF D>MOV DWORD PTR SS:[EBP-9C],16D55D0
0042B8F4 C785 68FFFFFF 1>MOV DWORD PTR SS:[EBP-98],16D5418
0042B8FE C785 6CFFFFFF 1>MOV DWORD PTR SS:[EBP-94],16D541C
0042B908 C785 70FFFFFF 1>MOV DWORD PTR SS:[EBP-90],16D5410
0042B912 C785 74FFFFFF 1>MOV DWORD PTR SS:[EBP-8C],16D5414
0042B91C C785 78FFFFFF 0>MOV DWORD PTR SS:[EBP-88],16D5408
0042B926 C785 7CFFFFFF 0>MOV DWORD PTR SS:[EBP-84],16D540C
0042B930 C745 80 00546D0>MOV DWORD PTR SS:[EBP-80],16D5400
0042B937 C745 84 9A516D0>MOV DWORD PTR SS:[EBP-7C],16D519A
0042B93E C745 88 18F52D0>MOV DWORD PTR SS:[EBP-78],12DF518
附脱壳文件!
点击下载:附件!