![]() |
|
|
|
#1
|
|||
|
|||
|
i dont know about x22 loader, but to just give it clarity, the tool hooks a function SafeArrayUnaccessData which is called after the assembly bytes are placed in the buffer to load, with this function hooked the paramater to this function points to an array of byes of assembly, which then are written to disk by the tool.
Can be used to dump assemblies from a native loader, or in case from .net crypters, obfuscators etc. because there is no debugger or anything else, it basically just works with complex samples too. Last edited by 0xall0c; 04-14-2022 at 17:00. |
| The Following User Says Thank You to 0xall0c For This Useful Post: | ||
niculaita (06-09-2022) | ||
|
#2
|
|||
|
|||
|
Quote:
Excellent work btw. Thank you. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| loaders in android | Molasar | General Discussion | 4 | 04-01-2016 17:22 |
| RE:loaders | hobgoblin | General Discussion | 10 | 04-29-2004 00:57 |