-
-
[分享]UPX完美脱壳脚本
-
发表于:
2013-11-15 15:50
31930
-
[FONT="Courier"]UPX 3.91w (Sep 30th 2013)
-------------------------
2013-09-30 17:51 305,152 upx391.exe[/FONT]
[FONT="Courier"]000001F0: 33 2E 39 31.00 55 50 58.21 0D 09 0E.0A 94 06 BB 3.91 UPX!
00000200: FF 0E 97 35.8F 93 86 19.00 AC 93 04.00 00 E6 18
00000210: 00 26 13 00.BA[/FONT]
[FONT="Courier"]000001F0: 33 2E 39 31.00 "3.91",压缩时使用的UPX版本ASCII串,无实际意义。
UPX1HEAD(header.S)
000001F5: 55 50 58 21 UPX_MAGIC_LE32: "UPX!",UPX Tag
000001F9: 0D 09 0E 0A version: 0D; format: 09(UPX_F_WIN32_PE); method: 0E(M_LZMA); level: 0A(--best)
000001FD: FFBB0694 uncompressed adler32
00000201: 8F35970E compressed adler32
00000205: 00198693 uncompressed length
00000209: 000493AC compressed length
0000020D: 0018E600 original file size
00000211: 26 13 00 BA filter id: 26; filter cto: 13; unused: 00; header checksum: BA[/FONT]
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课