Xylitol wrote:Disk Antivirus Professional
Original: https://www.virustotal.com/file/95e4027 ... 359625432/ > 21/46
Unpack: https://www.virustotal.com/file/41fc7f7 ... 359625192/ > 12/45
Network: Code: Select allGET /api/urls/?ts=f3626e3f&affid=00100 HTTP/1.1
Host: 112.121.178.189
---
GET /api/stats/install/?ts=f3626e3f&affid=00100&ver=3070024&group=dap HTTP/1.1
Host: 112.121.178.189
---
GET /p/?&lid=3070024&affid=00100&nid=8065D52C&group=dap HTTP/1.1
Host: kilopaybilling.com
thank you very much for unpacking this sample. :D
I try to unpack it by myself. I found 2 packers. The first packer is a manual packer. the second one, I guest PE Compact. I can dump process and fix IAT. My unpacked sample can be loaded and run. When I open my unpacked version with IDA, some functions are broken. I compare my version and yours, I see the difference from headers. My unpacked header has 6 sections : text, rdata, data, rsrc, reloc and mackt (from ImportREC) but your one has 3 sections: text. data and mackt. Can you help me to fix the header? I don't know how to do?
Thank you!!