What's new
RevTeam.Re - Reverse Engineering Team

Welcome Guest! Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox! Register and wait for our approve!

Unpackme challenge by Stingered

Stingered

Well-known member
Joined
Jan 11, 2022
Messages
117
Reaction score
785
Provide unpacked file as proof, as well as any details on how the unpack was accomplished.

View hidden content is available for registered users!


-thx
 

Stingered

Well-known member
Joined
Jan 11, 2022
Messages
117
Reaction score
785
Please, Log in to view quote content!
Update: New packed PE @daddypenguin , if you could pls take the time.

View hidden content is available for registered users!


Thank you for all the assistance!!

Also, it's kind of strange how much BIGGER the dumped PE was using Scylla (75kb bigger than the ORIG - wow).
 
Last edited:

daddypenguin

Well-known member
Joined
Mar 10, 2024
Messages
96
Reaction score
785
Please, Log in to view quote content!
The size difference is from the virtual address being a lot bigger than the disk addresses, as the section is currently empty the windows loader just puts null bytes in the region when in memory. When you fill it with data from the unpacking, when you dump it, it has to increase the disk addresses to fit on disk too

Please, Log in to view URLs content!
Basically the same 🙂
 
Top