jess LAND
       www.jessland.net
        Sponsored by:       
One eSecurity
www.one-esecurity.com
JISK Knowledgebase >>    About    News    Essentials    Architecture    FWs    IDS/IPS    Honeypots    Malware    Forensics   
  +  JSS Home    Projects    JSS Community    Events    News    Docs    About    Contact .

JISK > Malware > Analysis > Reverse Engineering > Windows > Packers > UPX Malware Section Map

UPX Packer

Content Leader: Jess Garcia - Last Updated: January 10, 2007


Gral Info

  • UPX: Ultimate Packer for eXecutables

Analysis

  • UPX PE Header has 3 sections:
    • UPX 0
    • UPX 1 - Where the decompressing routine is
      • End of the unpacking routine: JMP ; CALL ; POPAD ; JMP ; DB 00 ...
    • UPX 2 - Where the actual code is

Copyright © 2000-2008 Jessland - Jess Garcia's Website - All rights reserved.