Skip to content

Comment on Reversing a real-world 249 bytes backdoorparent

Comments

Hey I am the author of the blogpost. I have been reversing for a couple of years.

Usually, GDB just parses the ELF header to get the entry point. $ info file; in gdb should give you entrypoint of the binary almost always. In this case however the program has a corrupted section header, due to which gdb is not able to recognize the entry point. I dont exactly know which bytes in the header was corrupted, but apparently radare2 is able to get the entrypoint without much work. Should be fun to investigate more.

When you say it was undetected on VirusTotal, I suspect you really mean it was unknown, i.e. hadn't been submitted. Currently it has 3 scans and detections from the first.

2019-12-22T12:41:28 11/59

2019-12-22T19:19:28 13/60

2019-12-23T14:37:22 16/60

Thank you for your response. This was a very interesting blog post and I plan on reading more of your posts.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.