Home Artists Posts Import Register

Content

This is the first part of our series on removing the code obfuscation from the latest version of Lumma Stealer. In this VOD we identify the opaque predicate patterns that are preventing IDA from reconstructing the control flow and we begin to build an IDAPython script to remove them.

Sample

  • 18a065b740da441c636bce23fd72fc0f68e935956131973f15bf4918e317bf03 [UnpacMe]

Notes

Files

Live Stream VOD: Lumia Deobfuscation - Part 1

Comments

m4n0w4r

I was trying not to laugh when you entered the decimal value in IDA, until I heard "God, damn it!" I couldn't stop laughing anymore. :))))