ASPack 2.12

Check shell is ASPack2.12
Here Insert Picture Description
first see pushada first reaction esp's law.
Here Insert Picture Description
In esp at setting up the hardware execution breakpoints, then F9 to execute the next chart position
Here Insert Picture Description
to continue down the road and found a widely spaced return address most of the OEP is
Here Insert Picture Description
executed to unpack OEP
Here Insert Picture Description
set OEP's RVA is 0x1000
Here Insert Picture Description
dump IAT, for IAT file repair.
Here Insert Picture Description
Cut out invalid pointer
Here Insert Picture Description
dump Dump file to execute, view the execution results can be found to operate normally.
Here Insert Picture Description

Published 30 original articles · won praise 5 · Views 1925

Guess you like

Origin blog.csdn.net/AlexSmoker/article/details/104203324
Recommended