08-02-2017 , 12:40 AM
Published on Jul 15, 2017
I showcase a minimal FASM sample that prevents memory dumping. It erases its own header in memory so that dumping tools don't see a valid PE image anymore.
Follow me on Twitter: @struppigel
headererase.asm: https://pastebin.com/qVZiCpHM
Compile it with FASM: https://flatassembler.net/download.php
headererase.exe: https://www.hybrid-analysis.com/sampl...
- Category
- License
- Standard YouTube License
- Standard YouTube License