Flag: Tornado! Hurricane!


Article Abstract This paper is a direct descendent of my previous one regarding the metamorphic engine of the W32.Evol virus. I advise you to take a look at it before reading this one, or at least be acquainted with the subject of metamorphism. The focus of this paper is the special engine of the Lexotan32 virus.

The virus was released in 29A#6 Virus Magazine in 2002, the Annus Mirabilis of metamorphic viruses. The virus was created by the prolific VX coder, Vecna, and was one of the last complex creations of this kind. I could further elaborate on the genealogy of this virus, but I think it is sufficient to say that this virus is a culmination of many of the techniques developed throughout the author's career.

Full Article ...    Printer Friendly ...

Article Comments
mballano Posted: Friday, August 17 2007 01:54.18 CDT
Nice article ;-)

MohammadHosein Posted: Friday, August 17 2007 10:47.15 CDT
alot of details ...great work .

baibhav Posted: Friday, August 17 2007 10:48.22 CDT
Gud work ! Thanks for sharing !

vecna Posted: Thursday, August 23 2007 20:03.45 CDT
Congratulations for the article - its exact

adityaks Posted: Sunday, September 23 2007 23:40.22 CDT
nicely driven , very well

c0ck3dpist0l Posted: Tuesday, April 29 2008 07:54.10 CDT
it's cool! Thanks for sharing!

m4dnut Posted: Wednesday, July 9 2008 20:32.17 CDT
it's so cool~! thnaks for your effots.
i always cave a article like this. :)

lazyworm Posted: Wednesday, June 30 2010 20:25.49 CDT
very nice!I need it.

tgnice Posted: Saturday, June 18 2011 03:18.50 CDT
cool :)

redbone Posted: Tuesday, July 12 2011 02:56.10 CDT
good information ....

live2skull Posted: Sunday, May 8 2016 00:28.54 CDT
amazing article :)


Add New Comment
Comment:










There are 31,320 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit