Comments: [Remove text animation] manual shelling entry 16th articles MoleBox 2.x Patch IAT encryption [remove text author] weiyi75 [Dfcg] [author mailbox] weiyi75@sohu.com [author homepage] Dfcg official base camp 【 tools: Peid,
Remove text animation http://cnxhacker.net/donghua/crack/200607/245.html
[Untext title] manual shelling entry 16th MoleBox 2.x Patch IAT Encryption
[Author] weiyi75 [Dfcg]
[Author mailbox] weiyi75@sohu.com
[Author's homepage] official Dfcg base camp
[Tools] Peid, Ollydbg, ImportREC1.6f, Loadpe
[Shelling platform] Win2K/XP
[Software name] IMCaster icq e-Marketer
[Software Overview] IMCaster icq e-Marketer is a powerful ICQ instant information search tool. You can search for Online ICQ users based on different conditions (such as gender, age, country, or occupation) and send them information to increase the visibility of your website or enterprise.
[Software size] 2.61 M
[] Http://www.imcaster.com/Downloads/IMCastSetupEnt.exe or second brother recommended teaching download
[Shelling method] MoleBox 2. x. x-> Mole Studio [Overlay]
[Protection method] MoleBox compression Shell
[Shell removal statement] I am a little cainiao and may share with you a little bit :)
--------------------------------------------------------------------------------
[Shelling content]
Peid is used to check the shell, which is MoleBox 2. x. x-> Mole Studio [Overlay]. OD is loaded and run without any exception. It is determined as a compression shell.
As we can see in our previous solutions, IAT can be encrypted to decrypt IAT, Which is skipped.
Write the OD shelling script in one breath and write 16 articles, and then find that this IAT is encrypted. It's boring to write only a script to find the OEP. To write the script, you have to take off the shell first.
After shelling, the program cannot be run. In this case, you need to use Imprec to fix and introduce the function Table (Import Table)
Enter 8636F in Oep, click IT to automatically search, and then obtain the input information. nine pointers are not fixed.
The starting address of IAT is 89000, And the size is B80.
According to the Imprec prompt, the pointer at 89110 is encrypted.
Starting from here, you can also find an encrypted pointer.
OD load program, command line
Hardware 489110
Because the address previously written to this address is correct, and then the program encrypts this address as something Imprec does not know, we need to track this process.
Run F9
004D1237 8B45 F8 mov eax, dword ptr ss: [ebp-8]; imcast.00489110
004D123A 40 inc eax
004D123B 40 inc eax
004D123C 8945 F8 mov dword ptr ss: [ebp-8], eax
004D123F 0FB745 E2 movzx eax, word ptr ss: [ebp-1E]
004D1243 C1F8 08 sar eax, 8
004D1246 0FB74D E2 movzx ecx, word ptr ss: [ebp-1E]
Stack friendly prompt
0012FCD8 7FFDF000
0012 FCDC 47D047D0
0012FCE0 47334733
0012FCE4 5EBC5EBC
0012FCE8 72BF72BF
Continue to F9 3 times, pay attention to the stack-friendly prompt
004D13CE FF15 24804D00 call dword ptr ds: [; KERNEL32.GetProcAddress
004D13D4 8B4D F0 mov ecx, dword ptr ss: [ebp-10]
004D13D7 8901 mov dword ptr ds: [ecx], eax
004D13D9 EB 26 jmp short imcast.004D1401
004D13DB 8B55 F0 mov edx, dword ptr ss: [ebp-10]
004D13DE 8B02 mov eax, dword ptr ds: [edx]
004D13E0 25 FFFF0000 and eax, 0 FFFF
004D13E5 50 push eax
004D13E6 8B4D F4 mov ecx, dword ptr ss: [ebp-C]
004D13E9 51 push ecx
004D13EA FF15 24804D00 call dword ptr ds: [; KERNEL32.GetProcAddress
Stack friendly prompt
0012FE2C 77E7ED4C KERNEL32.SetFilePointer // This is the same as in EAX and is a correct pointer.
0012FE30 6BC4B4AC MFC42. #1576
0012FE34 0049428A imcast.0049428A
0012FE38 004943FE ASCII "KERNEL32.dll"
0012FE3C 00489110 imcast.00489110
0012FE40 77E60000 KERNEL32.77E60000
0012FE44 00493294 imcast.00493294
Now we
Dd 489110 saw 489100 encrypted.
004D13D9/EB 26 jmp short imcast.004D1401
004D1401 8B4D EC mov ecx, dword ptr ss: [ebp-14]; imcast.004943FE
004D1404 51 push ecx
004D1405 8B55 F0 mov edx, dword ptr ss: [ebp-10]
004D1408 52 push edx
004D1409 E8 12050000 call imcast.004D1920 // if a single step has passed here, it will be Over. Obviously, it is an encrypted Call, And the NOP program runs normally. Let's see it.
**************************************** **
004D1920 55 push ebp
004D1921 8BEC mov ebp, esp
004D1923 83EC 10 sub esp, 10
004D1926 C745 FC 00000000 mov dword ptr ss: [ebp-4], 0
004D192D 833D 30F04D00 00 cmp dword ptr ds: [4DF030], 0
004D1934 75 0A jnz short imcast.004D1940
004D1940 8B45 08 mov eax, dword ptr ss: [ebp 8] // note that EAX = 77E7ED4C is the correct pointer
004D1943 8B08 mov ecx, dword ptr ds: [eax]
004D1945 51 push ecx
004D1946 8B0D 30F04D00 mov ecx, dword ptr ds: [4DF030]
004D194C E8 AB380000 call imcast.004D51FC
004D1951 8945 F8 mov dword ptr ss: [ebp-8], eax
004D1954 837D F8 00 cmp dword ptr ss: [ebp-8], 0
004D1958 74 45 je short imcast.004D199F
004D195A 8D55 F0 lea edx, dword ptr ss: [ebp-10]
004D195D 52 push edx
004D195E 6A 04 push 4
004D1960 6A 04 push 4
004D1962 8B45 08 mov eax, dword ptr ss: [ebp 8]
004D1965 50 push eax
004D1966 FF15 70804D00 call dword ptr ds: [; KERNEL32.VirtualProtect
004D196C 85C0 test eax, eax
004D196E 75 0A jnz short imcast.004D197A
004D197A 8B4D 08 mov ecx, dword ptr ss: [ebp 8]
004D197D 8B55 F8 mov edx, dword ptr ss: [ebp-8]
004D1980 8B02 mov eax, dword ptr ds: [edx]
004D1982 8901 mov dword ptr ds: [ecx], eax // hateful here; imcast.004D490E
EAX = 004D490E dword ptr ds: [ecx] calculates the encrypted address 00489110. Actually, you can see the OD information box. We must make EAX the correct pointer. We can see that EAX is assigned at 004D1940, And the EAX at that time is the correct pointer.
This is easy.
004D1940 8B45 08 mov eax, dword ptr ss: [ebp 8]
Change
004D1940 8BC0 mov eax, eax; KERNEL32.SetFilePointer
004D1942 90 nop
Self-sufficiency
004D1984 8D4D F4 lea ecx, dword ptr ss: [ebp-C]
004D1987 51 push ecx
004D1988 8B55 F0 mov edx, dword ptr ss: [ebp-10]
004D198B 52 push edx
004D198C 6A 04 push 4
004D198E 8B45 08 & n