exe反汇编对比加壳两者区别

exe反汇编对比加壳两者区别

Deng YongJie's blog 714 2024-03-10

Virbox Protector试用版,商业版需付费。此效果较好-推荐

https://shell.virbox.com/down.html?keyword=&referrer=https%253A%252F%252Fcn.bing.com%252F&chatpage=https%253A%252F%252Fshell.virbox.com%252Fapply.html&landingPage=https%253A%252F%252Fshell.virbox.com%252F

image-20240510095921389
image-20240510095936128

Shielden加壳

image-20240510095833050

沙箱分析通过率2/27

image-20240510101412100

反汇编对比两者区别

未加壳

image-20240510101629525

已加壳

多了很多代码,就是要打乱逻辑,扰乱特征,目的为了绕过杀软

更高级的玩法是纯汇编,加壳加花指令扰乱,修改特征

image-20240510101709136