查壳
NSPack 3.x -> Liu Xing Ping *
用ESP定律可JMP后又回到没脱壳的入口点
od打开
004E6242 > 9C pushfd
004E6243 60 pushad
004E6244 E8 00000000 call 2.004E6249
004E6249 5D pop ebp
004E624A 83ED 07 sub ebp,7
004E624D 8D85 E2FEFFFF lea eax,dword ptr ss:[ebp-11E]
004E6253 8338 01 cmp dword ptr ds:[eax],1
004E6256 0F84 47020000 je 2.004E64A3
esp定律后 又回去了
004E64B8 9D popfd
004E64B9 - E9 84BDFCFF jmp 2.004B2242
004E64BE 8BB5 6EFEFFFF mov esi,dword ptr ss:[ebp-192]
004E64C4 0BF6 or esi,esi
004E64C6 0F84 97000000 je 2.004E6563
004E64CC 8B95 76FEFFFF mov edx,dword ptr ss:[ebp-18A]
还有用OD载入后文件不能运行被断下来
7C80FE2F > 6A 18 push 18
7C80FE31 68 D8FE807C push kernel32.7C80FED8
7C80FE36 E8 9026FFFF call kernel32.7C8024CB
7C80FE3B 8365 FC 00 and dword ptr ss:[ebp-4],0
7C80FE3F A1 E836887C mov eax,dword ptr ds:[7C8836E8]
7C80FE44 8B5D 08 mov ebx,dword ptr ss:[ebp+8]
7C80FE47 85C0 test eax,eax
7C80FE49 0F85 E1040300 jnz kernel32.7C840330
这样的怎么脱啊。高手指点下
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!