PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
- To: "FULLDISC" <full-disclosure@xxxxxxxxxxxxxxxxx>
- Subject: PAPER: Generic Unpacking of Self-modifying, Aggressive, Packed Binary Programs
- From: "Piotr Bania" <bania.piotr@xxxxxxxxx>
- Date: Mon, 25 May 2009 18:18:32 +0200
- Cc: "SBUGTRAQ" <bugtraq@xxxxxxxxxxxxxxxxx>
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:from:to:cc:subject :date:mime-version:content-type:content-transfer-encoding:x-priority :x-msmail-priority:x-mailer:x-mimeole; bh=U5avKvFgz5HgwmGOPr5cworxmwPKe2LmHj3+hLQtZZI=; b=j6LfEK5NoNoXHMy+lgszx0ngySphcfbTM0sWBCx+krjSnStEA10fCcsipy65BX61gC KzcCKNRGElmrwTVrluhXnm/ZBLdrePV56tHHcfELZIYlc7BqXnjhAtmEsNh4PT4LvIDV 46ZQUqqx5fS2HQ04NVJN5fgNimKt2DriYIWeM=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:from:to:cc:subject:date:mime-version:content-type :content-transfer-encoding:x-priority:x-msmail-priority:x-mailer :x-mimeole; b=PwoQeDWinTeE/nVvAmm+Znj0NlYQQVHEIxYUMxWV97U2GOsTeluyCgwlDGjw79ZlhU M3slnaKtX4rSLlZgQqBwkyoLe8JAZi6TIUUfdeplxfY/a3UW5k5bOfRGjbBP0KEqd0Lt RWxRH8Jcvzdf6Aybe4UpFRAKlQoM4POXTPz2w=
- List-help: <mailto:bugtraq-help@securityfocus.com>
- List-id: <bugtraq.list-id.securityfocus.com>
- List-post: <mailto:bugtraq@securityfocus.com>
- List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
- List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
- Mailing-list: contact bugtraq-help@xxxxxxxxxxxxxxxxx; run by ezmlm
ABSTRACT
Nowadays most of the malware applications are either packed or protected.
This techniques are applied especially to evade signature based detectors
and also to complicate the job of reverse engineers or security analysts.
The time one must spend on unpacking or decrypting malware layers is often
very long and in fact remains the most complicated task in the overall
process of malware analysis. In this report author proposes MmmBop as a
relatively new concept of using dynamic binary instrumentation techniques
for unpacking and bypassing detection by self-modifying and highly
aggressive packed binary code. MmmBop is able to deal with most of the known
and unknown packing algorithms and it is also suitable to successfully
bypass most of currently used anti-reversing tricks. [...]
Paper can be found at:
http://piotrbania.com/all/articles/pbania-dbi-unpacking2009.pdf
best regards,
pb
--
--------------------------------------------------------------------
Piotr Bania - <bania.piotr@xxxxxxxxx> - 0xCD, 0x19
Fingerprint: 413E 51C7 912E 3D4E A62A BFA4 1FF6 689F BE43 AC33
http://www.piotrbania.com - Key ID: 0xBE43AC33
--------------------------------------------------------------------
- "The more I learn about men, the more I love dogs."