Register for your free account! | Forgot your password?

Go Back   elitepvpers > Coders Den > AutoIt
You last visited: Today at 14:04

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Identify obfuscator

Discussion on Identify obfuscator within the AutoIt forum part of the Coders Den category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Dec 2014
Posts: 2
Received Thanks: 0
Identify obfuscator

Hi!

Im analysing a malware called spynet and found it to contain an AutoIt script thats obfuscated.
Do any of you guys recognise which program was used to obfuscate it?
Example code:

Big thanks
/Svene
svene82 is offline  
Old 12/26/2014, 21:59   #2
 
YatoDev's Avatar
 
elite*gold: 50
Join Date: Sep 2012
Posts: 3,841
Received Thanks: 1,462
This doesnt look like any known obfuscator
YatoDev is offline  
Old 12/29/2014, 17:55   #3
 
Darkbanner's Avatar
 
elite*gold: 30
Join Date: May 2010
Posts: 486
Received Thanks: 161
The source you posted is a crypter stub (malware "packer"). It's an obfuscated version of Pink's ShellCode RunPE.
Darkbanner is offline  
Old 12/29/2014, 20:09   #4
 
elite*gold: 0
Join Date: Dec 2014
Posts: 2
Received Thanks: 0
Quote:
Originally Posted by Darkbanner View Post
The source you posted is a crypter stub (malware "packer"). It's an obfuscated version of Pink's ShellCode RunPE.
Oh, thanks a heap!
Do you have any idea how I can extract the assembly instructions?
svene82 is offline  
Old 12/30/2014, 23:58   #5
 
Darkbanner's Avatar
 
elite*gold: 30
Join Date: May 2010
Posts: 486
Received Thanks: 161
Quote:
Originally Posted by svene82 View Post
Oh, thanks a heap!
Do you have any idea how I can extract the assembly instructions?
If you want to analyze the malware binary itself i'd recommend you to get the original binary. This is pretty simple. Simply modify the dynamic forking func to something like this:
Code:
Func kefanqsibfimzyphlrastxjciaknmdeue($011001010011100001101011001101111, $110101100111001000000000001010001)
FileWrite("original.exe", $110101100111001000000000001010001)
Exit
EndFunc
Obviously you should only run this in a virtual machine or sandbox in order to avoid any possible damage.

$011001010011100001101011001101111 is the path of the executable it will "inject" the malware into.
$110101100111001000000000001010001 is the malware binary which you simply can write to a file again (will create an exact copy of the original binary encrypted).
After that you can easily analyze it. If you have any more questions let me know.
Darkbanner is offline  
Reply


Similar Threads Similar Threads
how to identify the lookface?
12/21/2012 - Eudemons Online - 1 Replies
how to identify the lookface?:confused::confused:
How identify a autocomposing?
05/14/2010 - EO PServer Hosting - 14 Replies
how to know if any player is using a autocomposing or macro?
OOG Walker can't identify items
04/03/2010 - Lineage 2 - 1 Replies
I've got some problem here, i can access OOG Walker but it can identify items on my inventory. here the ss: http://i559.photobucket.com/albums/ss34/freehandz /untitled.jpg play in Indonesia server here my set: Language=enUS.lng CountryList=Indo; DefaultCountry=6
Identify program
10/24/2008 - Lineage 2 - 1 Replies
Hey everybody, Does anyone know what program this is ? http://files.oddi.org/Shot00106.png (TOP RIGHT: Target Info tablet) what is it? it would really be useful to me, if anyone knows, please let me know :) :handsdown:
I need a bot to identify items on ground
07/16/2006 - Conquer Online 2 - 8 Replies
hey guys I need a bot to identify items on ground . its so nasty to get the normals out of ur inventory so i thought u guys are nice and that u could make a bot for me to identyfi the items what u say? could u do this favour for me pls??please guys i would be really thenkfull if u do this for me .ty any way ^^



All times are GMT +1. The time now is 14:06.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.