Tools - Unpacking Exe32Pack

Exe32Pack is relatively unused packer in the malware world, but author stumble onto samples occasionally. Exe32Pack calls IsDebuggerPresent, but in addition to that it seems to do the check inline also, so setting a breakpoint at the IsDebuggerPresent API won’t suffice.

Read more…


Leave a Reply

You must be logged in to post a comment.