-
-
ARTeam: IDA plugin to depack aplib/lzma statically compressed data into IDA by deroko
-
发表于: 2008-9-24 16:26 2832
-
ARTeam: IDA plugin to depack aplib/lzma statically compressed data into IDA by deroko
2008-9-24 16:26
2832
Hi all,
just released a plugin for IDA 5.2 and following, to decompress aplib or lzma packed data in your target when analyzing with IDA.
The plugin supports aPlib which is quite common in malware, but there's also support for packman lzma compression, even if this one is very rare.
Run plugin by pressing CTRL+9 and you will be prompted with a window for unpacking or simply go to Edit->plugins->aplib depack
Full C sources are included, aswell. See the readme.txt for further details and instructions.
http://arteam.accessroot.com/releases.html
just released a plugin for IDA 5.2 and following, to decompress aplib or lzma packed data in your target when analyzing with IDA.
The plugin supports aPlib which is quite common in malware, but there's also support for packman lzma compression, even if this one is very rare.
Run plugin by pressing CTRL+9 and you will be prompted with a window for unpacking or simply go to Edit->plugins->aplib depack
Full C sources are included, aswell. See the readme.txt for further details and instructions.
http://arteam.accessroot.com/releases.html
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)
赞赏
他的文章
- [求助][ARTeam] Analyzing an Adobe Flash Malware (CVE-2011-2110) by +NCR/CRC! 6390
- [原创]ARTeam: new forum 2379
- [原创]ARTeam: Swimming into Trojan and Rootkit GameThief.Win32.Magania Hostile Code 1785
- [原创]ARTeam: [ARTUT] Introduction To Malware Techniques and Logics Part 1 2762
- [原创]ARTeam: Armag3ddon 1.6f by condzero 4863
看原图
赞赏
雪币:
留言: