[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20040131114633.GA1058@ergo.nruns.com>
From: jan.muenther at nruns.com (jan.muenther@...ns.com)
Subject: MyDoom download info.
> It's still UPX packed, but it won't unpack with "UPX -d" because the author
> used a simple UPX scrambler. Either undo what he did or unpack it manually
> and you'll see all the code.
It actually un-UPX-ed just fine for me. What version have you been trying?
It disassembled nicely after that. The only other obfuscation (apart from
quite a bit of wild jmp'ing around) is the rot13'ed strings, which isn't,
erm, too challenging. Anything else? I've only looked quickly at it during a
train ride.
Powered by blists - more mailing lists