A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #29286  by r00tMe
 Thu Sep 29, 2016 11:03 pm
I am trying analyze a ransomeware which is not packed is ensured by using PEiD and ExeInfo packer detector and mostly in ensured by checking the section or that malware. All normal section.

That file has imports in import section but does not have any code / text section nor any functions except start function only.
I provided screenshot below please help.
Thanks
Rootme

Image

Image
 #29288  by sysopfb
 Fri Sep 30, 2016 12:57 am
Can you attach a sample?

Just because PEiD and exeinfo do not detected it to be packed or crypted does not mean it is not packed it just means it's not packed with a packer/crypter that has been signatured
 #29297  by r00tMe
 Fri Sep 30, 2016 2:29 am
sysopfb wrote:Can you attach a sample?

Just because PEiD and exeinfo do not detected it to be packed or crypted does not mean it is not packed it just means it's not packed with a packer/crypter that has been signatured
How to unpack Qadas Malware it's similar to this malware !
Thanks