BreakingMalware / Selfie

A Tool to Unpack Self-Modifying Code using DynamoRIO
141 stars 37 forks source link

Nothing happends #1

Open jonaslejon opened 9 years ago

jonaslejon commented 9 years ago

Hello, i've been trying Selfie with DynamoRIO but nothing happends. Maybe i'm missing something?

screenshot

BreakingMalware commented 9 years ago

Hi jonaslejon, Thanks for using the tool! It looks like you are trying to use selfie against the upx packing/unpacking tool, why do u want something to be triggered? Selfie is a tool to unpack self modifying packers, u need to use it against malware that during the unpacking routine overwrites themselves with the unpacked code. Try using the samples i have provided in the readme file, if you want/need some more examples just let me know and I will send you the hashes. Hope it helps, Tomer