手工脱一个armadillo的壳,就不知道~~号的地方
是不是magic jmp的地方?
00AF5331 MOV ECX,DWORD PTR DS:[B1D860]
00AF5337 MOV DWORD PTR DS:[ESI+ECX],EAX
00AF533A MOV EAX,DWORD PTR DS:[B1D860]
00AF533F CMP DWORD PTR DS:[ESI+EAX],EDI
00AF5342 JNZ SHORT 00AF535A
00AF5344 LEA EAX,DWORD PTR SS:[EBP-14C]
00AF534A PUSH EAX
00AF534B CALL DWORD PTR DS:[B150B8]
00AF5351 MOV ECX,DWORD PTR DS:[B1D860]
00AF5357 MOV DWORD PTR DS:[ESI+ECX],EAX
00AF535A MOV EAX,DWORD PTR DS:[B1D860]
00AF535F CMP DWORD PTR DS:[ESI+EAX],EDI
00AF5362 JE 00AF5415 ; magic jmp
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
这里是不是magic jmp??
这里改为JMP 00AF5415并不能避免iat加密?
大家觉得哪??
00AF5368 00AF535A XOR ECX,ECX
00AF536A MOV EAX,DWORD PTR DS:[EBX]
00AF536C CMP DWORD PTR DS:[EAX],EDI
00AF536E JE SHORT 00AF5376
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!