mirror of
https://github.com/SabreTools/BinaryObjectScanner.git
synced 2026-02-03 21:29:23 +00:00
[Packer] Add ASPack/ASProtect detection #52
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @TheRogueArchivist on GitHub (Jan 12, 2022).
Both packers are actually still around today, though the new version of ASProtect seems to referred to as ASProtect 32/64. ASProtect 2.x seems to be referred to as ASProtect SKE, with either one version in common use, or PiD's version detection lacking. ASPack still seems to be available under the same name, ASPack identification should be relatively easy, as I see "aspack" inside of the header of the samples I've seen. I haven't seen that string, nor any equivalent, in ASProtect. This makes sense, since ASPack seems to be advertised as a more budget friendly packer that doesn't have as much emphasis on security. I assume ASProtect is essentially a form of ASPack+Security, but that's just a guess.
Official site: http://www.aspack.com/
ASPack unpacker: https://gist.github.com/abhisek/3659931
ASProtect RE: https://github.com/pstolarz/asprext
@mnadareski commented on GitHub (Jul 12, 2022):
https://unprotect.it/technique/aspack/
@mnadareski commented on GitHub (Jul 12, 2022):
Implemented in
8fb42bc12d