New User, Welcome!     Login

PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs

From: "Piotr Bania" <bania piotr gmail com>
To: "FULLDISC" <full-disclosure lists grok org uk>
Cc: "SBUGTRAQ" <bugtraq securityfocus com>
Subject: PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
Date: Mon - May 25, 2009 09:32 AM



ABSTRACT

Nowadays most of the malware applications are either packed or protected. 
This techniques are applied especially to evade signature based detectors 
and also to complicate the job of reverse engineers or security analysts. 
The time one must spend on unpacking or decrypting malware layers is often 
very long and in fact remains the most complicated task in the overall 
process of malware analysis. In this report author proposes MmmBop as a 
relatively new concept of using dynamic binary instrumentation techniques 
for unpacking and bypassing detection by self-modifying and highly 
aggressive packed binary code. MmmBop is able to deal with most of the known 
and unknown packing algorithms and it is also suitable to successfully 
bypass most of currently used anti-reversing tricks.  [...]


Paper can be found at:
http://piotrbania.com/all/articles/pbania-dbi-unpacking2009.pdf


best regards,
pb


-- 
--------------------------------------------------------------------
Piotr Bania - <bania.piotr@gmail.com> - 0xCD, 0x19
Fingerprint: 413E 51C7 912E 3D4E A62A  BFA4 1FF6 689F BE43 AC33
http://www.piotrbania.com  - Key ID: 0xBE43AC33
--------------------------------------------------------------------

               - "The more I learn about men, the more I love dogs."





Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!