一、病毒信息
病毒名称:骷髅病毒
文件名称:
d5dac2456fa6758480e946aa6a1597399bf0b9e7df1383c7ba568559b969a827
文件格式:
EXEx86
文件类型(Magic):
PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
文件大小:
66.50KB
SHA256:
d5dac2456fa6758480e946aa6a1597399bf0b9e7df1383c7ba568559b969a827
SHA1:
c660516ceb64fb9373b297973f962398ee6d1879
MD5:
77031bafa4c641c28ab9f624a15766b0
CRC32:
79C2B4D8
SSDEEP:
768:CGBwjSgvnyXXQkZuzQEN8Fs+U5MV4nb42sWAw/CQd07d21a1XWCIqrY+9GbRa:PBzgvnyXgkwg0sl5Qd07k1sXvr
TLSH:
T1D0635C1BAD45D0A1E00600389519FAFF66A76C71C51EAA53FB80FD827CB8587F8B9D07
AuthentiHash:
4A58C42F188D69E5EC03A22F02C0C9AB8D6B8D0B39C01DD7CA05DD97074509A2
peHashNG:
15fe9808e4c7996169d2f7d72ab94995e16510faac3b23d090f9c6ccbcceaa0f
RichHash:
c5755a1d31fa664aef391971dfc1145d
impfuzzy:
24:MEpZQCB8u1wX1siuLVuLQjuyPq0jcfLGDQj1E5T0v+GO9CJI/qkbJnBevrzvoLWZ:prwX1Euljix02G+CJI/q0JBevrzri+
ImpHash:
ccbcdba127c40ad07597791950e62759
ICON SHA256:
ffac9d7025d1e7d091fc5449da7401928cff13c3083719ca38b4518042608ef9
ICON DHash:
336171172d330c0d
Tags:
exe,section_name_exception,lang_chinese
二、环境准备
系统 |
杀毒软件 |
调试器 |
Win7x86 |
火绒剑 |
IDA,OD |
三、脱壳
样本拖到PEID中,可以看到是有UXP壳:


首先脱壳,样本拖入OD:

