OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
unpacking UPX or PE-packed binaries

From: Karma (stevefrij.com)
Date: Thu Apr 22 2004 - 21:25:38 CDT


Hi List,

Just interested in how AV R&D companies unpack worms with complex UPX and PE
pack protocols.

Been trying to disect the recent Gaobot variants and getting no where with
my generic UPX-unpacker. Since this is more and more commonly used, I
thought I would be wise to consult the Lists.

Cheers,

Karma