4 ms·
I suggest taking a look at the slides, which show how much trickery is involved: https://github.com/xoreaxeaxeax/movfuscator/raw/master/slides/the_movfuscator_r
by cautious_int 11y ago
I suggest taking a look at the slides, which show how much trickery is involved: https://github.com/xoreaxeaxeax/movfuscator/raw/master/slides/the_movfuscator_recon_2015.pdf https://github.com/xoreaxeaxeax/movfuscator/raw/master/slide...
- patio11 11y agoStrongest possible +1 for the slides if you are at all interested in low-level alchemy. Also see slide 109 for the beginning of a shadow argument that this might actually have some real-world utility, in that the long list of MOVs is virtually immune to comprehension by existing reverse engineering tools and practices.
- ORioN63 11y agoOn the other hand you could compile it back to regular assembly and use them.