<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>RCE Blog</title>
	<atom:link href="http://antelox.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://antelox.wordpress.com</link>
	<description></description>
	<lastBuildDate>Sun, 29 Jan 2012 10:00:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='antelox.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>RCE Blog</title>
		<link>http://antelox.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://antelox.wordpress.com/osd.xml" title="RCE Blog" />
	<atom:link rel='hub' href='http://antelox.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Moved to Blogspot</title>
		<link>http://antelox.wordpress.com/2011/09/07/moved-to-blogspot/</link>
		<comments>http://antelox.wordpress.com/2011/09/07/moved-to-blogspot/#comments</comments>
		<pubDate>Wed, 07 Sep 2011 08:55:09 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=225</guid>
		<description><![CDATA[I finally decided to move on blogspot. So for Tutorials, News, Analysis and much more go to: http://antelox.blogspot.com Bye bye WordPress!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=225&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I finally decided to move on blogspot. So for Tutorials, News, Analysis and much more go to: http://antelox.blogspot.com</p>
<p>Bye bye WordPress!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/225/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=225&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2011/09/07/moved-to-blogspot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>
	</item>
		<item>
		<title>Just some Acrobat exploits</title>
		<link>http://antelox.wordpress.com/2010/07/11/just-some-acrobat-exploits/</link>
		<comments>http://antelox.wordpress.com/2010/07/11/just-some-acrobat-exploits/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 19:26:09 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=158</guid>
		<description><![CDATA[In this second post I will explain the functions in the javascript code carved out used to exploit the Acrobat vulnerability. First of all we take a look at the function that acts as a version-check of Acrobat with which the victim opened to read the pdf infected. This is the function: the function name [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=158&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In this second post I will explain the functions in the javascript code carved out used to exploit the <strong>Acrobat vulnerability</strong>.</p>
<p>First of all we take a look at the function that acts as a version-check of Acrobat with which the victim opened to read the pdf infected.</p>
<p>This is the function:</p>
<p><img src="http://antelox.files.wordpress.com/2010/07/vcheck.png?w=450" alt="" /></p>
<p>the function name is <strong>GDUvmppC ()</strong>. Inside, <strong>yVXd</strong> variable is declared, and through <strong>app.viewerVersion.toString ()</strong> function is initialized with the respective version number of Acrobat. At last, through <em>Iteration</em>s will start the respective exploit depending on the detected version.</p>
<p>If the version is <em>less</em> than <strong>8</strong>, then performs the <strong>waDmT ()</strong> function.<br />
If the version is <em>greater</em> than <strong>8</strong>, then performs the <strong>FdAY ()</strong> function.<br />
If the version is <em>less</em> than <strong>9.1</strong>, then performs the <strong>mLU()</strong> function.<br />
If the version is <em>less</em> than version <strong>9.2</strong>, then performs the <strong>breakfast()</strong> function.</p>
<p>As you can see there are 4 functions.</p>
<p>The waDmT() function exploits the <strong>collectEmailInfo</strong> vulnerability<br />
-&gt; collectEmailInfo({ subj:&#8221;",msg:mmk })</p>
<p><a href="http://antelox.files.wordpress.com/2010/07/wadmt2.png" target="_blank"><img class="aligncenter size-full wp-image-179" title="waDmT" src="http://antelox.files.wordpress.com/2010/07/wadmt2.png?w=450&#038;h=245" alt="" width="450" height="245" /></a></p>
<p>The FdAY() function exploits the <strong>util.printf</strong> vulnerability<br />
-&gt; util.printf(&#8220;%45000f&#8221;,uzpymeSR)</p>
<p><a href="http://antelox.files.wordpress.com/2010/07/fday2.png" target="_blank"><img class="aligncenter size-full wp-image-177" title="FdAY" src="http://antelox.files.wordpress.com/2010/07/fday2.png?w=450&#038;h=244" alt="" width="450" height="244" /></a></p>
<p>The mLU() function exploits the <strong>getIcon</strong> vulnerability<br />
-&gt; app.doc.Collab.getIcon(gGsYFcss)</p>
<p><a href="http://antelox.files.wordpress.com/2010/07/mlu2.png" target="_blank"><img class="aligncenter size-full wp-image-178" title="mLU" src="http://antelox.files.wordpress.com/2010/07/mlu2.png?w=450&#038;h=246" alt="" width="450" height="246" /></a></p>
<p>The breakfast() function exploits the <strong>util.printd</strong> vulnerability<br />
-&gt; util.printd(GDagaCuyNfRSFzaSZLO, new Date())</p>
<p><a href="http://antelox.files.wordpress.com/2010/07/breakfast2.png" target="_blank"><img class="aligncenter size-full wp-image-176" title="breakfast" src="http://antelox.files.wordpress.com/2010/07/breakfast2.png?w=450&#038;h=170" alt="" width="450" height="170" /></a></p>
<p>All functions contain <em>shellcode</em>, and in particular we find them some interesting links:</p>
<p><em>- http://*/yogetheadshot.php?ids=UdPDF<br />
- http://*/yogetheadshot.php</em></p>
<p>From these two links are downloaded same malware. Malware are identical because they are only called from two different links depending on the version of Acrobat <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>In the next post I&#8217;ll try to explain what makes the malware downloaded through the PDF.</p>
<p>Bye, see you in the next post. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/158/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/158/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/158/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=158&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/07/11/just-some-acrobat-exploits/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/07/vcheck.png" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/07/wadmt2.png" medium="image">
			<media:title type="html">waDmT</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/07/fday2.png" medium="image">
			<media:title type="html">FdAY</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/07/mlu2.png" medium="image">
			<media:title type="html">mLU</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/07/breakfast2.png" medium="image">
			<media:title type="html">breakfast</media:title>
		</media:content>
	</item>
		<item>
		<title>Analysis of a malformed and exploited PDF</title>
		<link>http://antelox.wordpress.com/2010/07/11/analysis-of-a-malformed-and-exploited-pdf/</link>
		<comments>http://antelox.wordpress.com/2010/07/11/analysis-of-a-malformed-and-exploited-pdf/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 12:17:08 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=132</guid>
		<description><![CDATA[Hi today I&#8217;m going to analyze an infected PDF which allows Acrobat exploitation The file target is called soreheadprattler.pdf md5: AF485196F31F66B07D87E63DFCA41239 At moment when I&#8217;m writing, referring to Virustotal, PDF is detected by 29.27% of AV ( 12/41 ), to be honest, very low rate to the potential of the exploit in question. This PDF, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=132&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hi<br />
today I&#8217;m going to analyze an infected PDF which allows Acrobat exploitation <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The file target is called <strong>soreheadprattler.pdf</strong><br />
md5: AF485196F31F66B07D87E63DFCA41239<br />
At moment when I&#8217;m writing, referring to Virustotal, PDF is detected by <em>29.27%</em> of AV ( <em>12/41</em> ), to be honest, very low rate to the potential of the exploit in question. This PDF, using the Sophos nomenclatur, is identified as <em>Troj/PDFJs-LJ</em></p>
<p>Let&#8217;s go to analyze the PDF.</p>
<p>First of all I take this opportunity to thank my friend <strong>Daniel</strong> for giving me the opportunity to act as tester, being still under development. Thx =)<br />
The tool in question is <strong>PDF Insider</strong>, for more info visit <em>ntcore.com</em>.</p>
<p>Opening the PDF file in PDF Insider we immediately notice a malformation.</p>
<p><img src="http://antelox.files.wordpress.com/2010/07/xref.jpg?w=450" alt="" /></p>
<p>We warned of an unresolved xref. The <strong>xref keyword</strong> ( Cross-reference ) in PDF format are used to search the objects, in fact for this problem we have no object apparently, but this is not a problem because PDF Insider provides us special functions for finding objects to solve these mishaps <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> .<br />
In fact clicking on Detect Object we get 4 objects: 1.0, 2.0, 3.0 and <em>4.0</em>.<br />
Here a screenshot:</p>
<p><img src="http://antelox.files.wordpress.com/2010/07/object.jpg?w=450" alt="" /></p>
<p>Each object may contain the JS code and / or compressed Stream. Of course in our case being merely 4 would not be a problem to go through each object and check for interesting content, but if it was a pdf with many object was a real suicide, unless you are masochistic <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> .</p>
<p>PDF Insider intervenes again to our aid, showing what object or stream contains JavaScript code.</p>
<p><img src="http://antelox.files.wordpress.com/2010/07/detected.jpg?w=450" alt="" /></p>
<p>We can see that the 4.0 object contains both Stream ( compressed ) and Javascript code, as well as being the only one!<br />
But let&#8217;s go to see what&#8217;s interesting inside it:</p>
<p><img src="http://antelox.files.wordpress.com/2010/07/filter.jpg?w=450" alt="" /></p>
<p>We note immediately between the Info, interesting <strong>Filters</strong>:</p>
<p>- <strong>LZWDecode</strong>: This indicats that data are compressed, as I said before. LZW ( Lempel-Ziv-Welsh ) is more used as a data compression algorithm in PDF;<br />
- <strong>ASCII85Decode</strong>: Other encryption algorithm, also known as Base85 encoding used for communication protocols;<br />
- <strong>ASCIIHexDecode</strong>: Decodes data encoded in an ASCII hexadecimal<br />
representation, reproducing the original binary data;<br />
- <strong>RLE</strong>: The RLE ( Run Length Decode ) decompresses data encoded using a byte-oriented run-length encoding algorithm, reproducing the original text or binary data.</p>
<p>Now that we have this info we can also do proper analysis of 4.0 Object. PDF Insider supports LZW algorithm and thus is able to decompress it easily to show the contents of the Stream:</p>
<p><a href="http://antelox.files.wordpress.com/2010/07/b0b.jpg" target="_blank"><img src="http://antelox.files.wordpress.com/2010/07/b0b.jpg?w=450&#038;h=218" alt="" title="B0b" width="450" height="218" class="aligncenter size-full wp-image-140" /></a></p>
<p>What is immediately evident is the declaration of a variable, specifically named <strong>B0b</strong>. Skip to the eye because it contains a very long string. But scrolldown to see how this variable is used!</p>
<p>As I thought! It is used in a function that operates a character replacement. It&#8217;s easy to see that there are many &#8220;<strong>@</strong>&#8221; and indeed this character will be replaced by another. Better explain the whole, below the rest of the code:</p>
<p><img src="http://antelox.files.wordpress.com/2010/07/code.jpg?w=450" alt="" /></p>
<p>First are declared some variables. At <strong>z</strong> variable is assigned the value <strong>app.doc</strong> which is then chained to complete the function with <strong>syncAnnotScan()</strong>.<br />
Immediatly below B0b varaible is worked. <strong>BOb.replace (/ @ / g, String.fromCharCode (32-1 +6)</strong> makes a global research (-&gt; /g) throughout the data block to find &#8220;@&#8221; char and then replace it by the function <strong>String.fromCharCode ()</strong> with the symbol related to hex code 37 (32-1 +6 == 37) that corresponds to the symbol &#8220;<strong>%</strong>&#8220;. Well, we obtein a new data block:</p>
<p><a href="http://antelox.files.wordpress.com/2010/07/replaced.jpg" target="_blank"><img src="http://antelox.files.wordpress.com/2010/07/replaced.jpg?w=450&#038;h=180" alt="" title="replaced" width="450" height="180" class="aligncenter size-full wp-image-145" /></a></p>
<p>Before I mentioned app.doc and syncAnnotScan so now I report the explanation from Adobe documentation:</p>
<p>- <strong>app</strong>: The app object is a static object that represents the Acrobat application itself. It offers a<br />
number of Acrobat-specific functions in addition to a variety of utility routines and<br />
convenience functions.</p>
<p>- <strong>doc</strong>: The doc object is the primary interface to the PDF document, and it can be used to access<br />
and manipulate its content. The doc object provides the interfaces between a PDF<br />
document open in the viewer and the JavaScript interpreter.</p>
<p>- <strong>syncAnnotScan</strong>: The syncAnnotScan method guarantees that all annotations in the documents are scanned.</p>
<p>Once we&#8217;ve done all, we find the classic <strong>eval ()</strong> function and inside the <strong>unescape()</strong> function.<br />
First of all through the unescape function data block which we talked about before is decoded getting the horrible javascript code and then run through eval () function, so <strong>oN ()</strong>.</p>
<p>In the next post I will explain how functions in the javascript code, which we got after these simple steps, are used to exploit vulnerabilities in various versions of Adobe.</p>
<p>Bye, see you in the next post. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/132/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/132/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/132/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=132&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/07/11/analysis-of-a-malformed-and-exploited-pdf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/07/xref.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/07/object.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/07/detected.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/07/filter.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/07/b0b.jpg" medium="image">
			<media:title type="html">B0b</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/07/code.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/07/replaced.jpg" medium="image">
			<media:title type="html">replaced</media:title>
		</media:content>
	</item>
		<item>
		<title>Qt Creator 2.0 is Out!</title>
		<link>http://antelox.wordpress.com/2010/06/25/qt-creator-2-0-is-out/</link>
		<comments>http://antelox.wordpress.com/2010/06/25/qt-creator-2-0-is-out/#comments</comments>
		<pubDate>Fri, 25 Jun 2010 18:14:22 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=125</guid>
		<description><![CDATA[Then OllyDbg 2.0 news, another one good; Qt Creator 2.0 is out. This last version integrates more nice features, improvements and it&#8217;s makes to develop more fast and easy with mobile development kit. Qt Libraries 4.6.3 is also out. More info: Nokia today released Qt Creator 2.0, an updated version of its cross-platform integrated development [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=125&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Then OllyDbg 2.0 news, another one good; <em>Qt Creator 2.0</em> is out. This last version integrates more nice features, improvements and it&#8217;s makes to develop more fast and easy with mobile development kit. Qt Libraries <em>4.6.3</em> is also out. More info:</p>
<blockquote><p>Nokia today released Qt Creator 2.0, an updated version of its cross-platform integrated development environment (IDE) for use with the Qt framework.  Qt Creator 2.0 brings a range of new features specifically designed to make mobile development for Symbian, MeeGo and other platforms faster and easier.</p>
<p>Qt Creator 2.0 is available as part of the Nokia Qt SDK 1.0 – also released today – as part of an updated build of the Qt SDK, or as a standalone binary or source download. All Qt releases are available for download from http://qt.nokia.com/downloads.</p>
<p>Qt Creator 2.0 part of Nokia Qt SDK 1.0</p>
<p>Released today, the Nokia Qt SDK provides developers with a single package containing all tools they need – including Qt Creator and the Qt framework – to code, simulate, debug and build cross-platform applications for Symbian, Maemo, and in the future, MeeGo devices.  For more information, and to download, visit http://www.forum.nokia.com/Develop/Qt/Tools/.</p>
<p>For a detailed list of changes introduced in Qt Creator 2.0, consult the changes file found in the packages or browse the information in the Qt Developer Zone at http://qt.nokia.com/developer/changes/changes-qtcreator-2.0.</p>
<p>New Qt APIs for Mobile Development Updates</p>
<p>Also released today is an update to the New Qt APIs for mobile development – Mobility 1.0.1. The patch release provides new Symbian backends, finalizes the Qt Multimedia API and includes bug fixes.  For more information, visit the New Qt APIs for mobile development catalog.</p></blockquote>
<p>To download SDK: <a href="http://get.qt.nokia.com/">Qt</a></p>
<p>Bye. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/125/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=125&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/06/25/qt-creator-2-0-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>
	</item>
		<item>
		<title>OllyDbg 2.0 ini File Configuration</title>
		<link>http://antelox.wordpress.com/2010/06/13/ollydbg-2-0-ini-file-configuration/</link>
		<comments>http://antelox.wordpress.com/2010/06/13/ollydbg-2-0-ini-file-configuration/#comments</comments>
		<pubDate>Sun, 13 Jun 2010 17:25:22 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=119</guid>
		<description><![CDATA[Here the OllyDbg 2.0&#8242;s ini file which I have changed to improve the appearance and other general settings of our favorite debugger To Download: ini file N.B. : Some options about code highlighting I&#8217;ve taken from an old ini file for 1.10 Olly version, made by one my friend. If you have some changes to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=119&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here the OllyDbg 2.0&#8242;s ini file which I have changed to improve the appearance and other general settings of our favorite debugger <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>To Download: <A HREF="http://www.megaupload.com/?d=X6FMY4JW"> ini file </A></p>
<p>N.B. : <em>Some options about code highlighting I&#8217;ve taken from an old ini file for 1.10 Olly version, made by one my friend</em>.</p>
<p>If you have some changes to hint me, I&#8217;ll be happy to add them!</p>
<p>Bye, see you in the next post. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=119&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/06/13/ollydbg-2-0-ini-file-configuration/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>
	</item>
		<item>
		<title>Olly 2.0 Final Release is Out!</title>
		<link>http://antelox.wordpress.com/2010/06/04/olly-2-0-final-release-is-out/</link>
		<comments>http://antelox.wordpress.com/2010/06/04/olly-2-0-final-release-is-out/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 22:52:52 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=113</guid>
		<description><![CDATA[Finally, after a couple of years of development and beta release, final version is out! One very good news Here some info from Olly&#8217;s Home Page: You haven&#8217;t heard much about OllyDbg 2.0 for a long time. Unfortunately, I am permanently busy and have not much free time. But there is a progress. I have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=113&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div dir="ltr">Finally, after a couple of years of development and beta release,  final version is out! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  One very good news</div>
<div dir="ltr"></div>
<div dir="ltr">Here some info from Olly&#8217;s Home Page:</div>
<blockquote><p>You haven&#8217;t heard much about OllyDbg 2.0 for a long time. Unfortunately, I am permanently busy and have not much free time.</p>
<p>But there is a progress. I have made many changes and bugfixes, among them:</p>
<p>- prn bombed me with many, many ideas and found bugs. For example, he reported massive problems with UNICODE filenames that use extended charset. And no, Windows doesn&#8217;t convert them automatically to ASCII. As OllyDbg is still an ASCII application, now I convert such names to old 8.3 DOS format.  Active breakpoint were not marked in the corresponding breakpoint windows; memory breaks were falsely hinted, and so on, and so forth&#8230; Thank you, and please don&#8217;t stop!<br />
- William reported bugs with PUSH AH etc. Yes, there are no such commands, but OllyDbg v2.0 happily assembled them.<br />
- Keyboard shortcuts did not work in Edit/Search dialog. Reported by mailnew2ster.<br />
- Ange gave me the complete list of 80&#215;86 commands as a compiled executable file. He found many assembly/disassembly errors. With his list, we were able to remove them. He also criticided my &#8220;English&#8221; help file for grammatical errors, silly old me!<br />
- Eric, deepzero and karmany reported problems with highlighting and comments.<br />
- John found out that Always on top may hide error messages.<br />
- Aaron and many other reported crash on structure decoding, namely on those where some elements were unnamed, like elements of array.<br />
- I thought that exe/dll with 5 MB code section is really large, until Ivar sent me an executable which code section was 83,079,168 bytes (SEVENTY NINE MEGABYTES) long! Analysis attempted to allocate more than 1,5 GB of memory &#8211; still not a problem, but due to fragmentation, my memory manager was unable to execute the request. It was necessary to redesign it.<br />
- Rinze pointed at problem with memory breakpoints on stack. OllyDbg did not check memory addressed indirectly by ESP.<br />
- NCR asked for the search for process name in Attach window by typing its name.<br />
- numax suggested list of user comments.<br />
- Hopefully OllyDbg will support Chinese and Japanese fonts in dialog boxes (Edit/Search data), main issue that we tried to debug together with locklose. It should work, but I can give you no warranty. Please check.<br />
- And, a couple of days ago, edemko discovered that conditional jums on LOOPZ/LOOPNZ are falsely predicted. This was the last bug corrected in the version 2.00.</p>
<p>The list is far from complete, altogether I received more than 100 reports and suggestions. So for all contributors: Without your help, OllyDbg 2.0 would not exist. Thank you very much!</p>
<p>And now about my plans for the future. Probably I will convert OllyDbg to UNICODE. There are too many places where ASCII is not fully supported by Windows, like file names with extended charset or controls that don&#8217;t receive WM_WCHAR. This will mean end for Win95 and WinME users. Those who use WinNT, 2000, XP and Win7 will notice nothing. Of course, plugins will be forced to UNICODE, too.</p>
<p>I plan to introduce experimental plugin support in the version 2.01. The interface is not yet defined. If you have written plugins for v1.10, please send me your ideas and suggestions now!</p>
<p>Version 2.01 will finally work under 64-bit Windows. Probably I will start developing 64-bit OllyDbg, but this depends on my free time.</p></blockquote>
<p>This last news more interesting!!! OllyDbg is Uber</p>
<p>To download it: <em>http://www.ollydbg.de/version2.html</em></p>
<p>Bye. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=113&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/06/04/olly-2-0-final-release-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>
	</item>
		<item>
		<title>Just another MSN’s fake address</title>
		<link>http://antelox.wordpress.com/2010/05/30/just-another-msns-fake-address-2/</link>
		<comments>http://antelox.wordpress.com/2010/05/30/just-another-msns-fake-address-2/#comments</comments>
		<pubDate>Sun, 30 May 2010 11:56:56 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=93</guid>
		<description><![CDATA[Hi all another fake address I have discovered these days. It&#8217;s of the same family of my first previous post regard this field. The address today is: NikiaPortisienrh@hotmail.com The behaviour is the same of the previous contacts analyzed other times. Let&#8217;s go to see a chat form: As you can see after a couple of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=93&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hi all</p>
<p>another fake address I have discovered these days. It&#8217;s of the same family of my first previous post regard this field.</p>
<p>The address today is: <strong>NikiaPortisienrh@hotmail.com</strong></p>
<p>The behaviour is the same of the previous contacts analyzed other times. Let&#8217;s go to see a chat form:</p>
<p><img src="http://antelox.files.wordpress.com/2010/05/form.jpg?w=450" alt="" /></p>
<p>As you can see after a couple of messages, the contact invites the victim to go to an address to see the pseudo-girlfriend in cam, after that the victim has accepted one invite. The link sended by the fake account is: <strong>http://shortlinks.co.uk/1mc3</strong><br />
This link redirects the victim at a main URL where the fraud acts: <strong>http://www.webcamcrush.com/StephiesAss20</strong>. This URL is presents also in Personal Message form.</p>
<p>As you can understand the page is the same of the other fake accounts of the previous analysis, as it had announced. Here a screenshot:</p>
<p style="text-align:center;"><a href="http://antelox.files.wordpress.com/2010/05/page1.jpg" target="_blank"><img class="aligncenter size-medium wp-image-97" title="Page" src="http://antelox.files.wordpress.com/2010/05/page1.jpg?w=300&#038;h=152" alt="" width="300" height="152" /></a></p>
<p>To the right there is a form to chat with the girl. So, typing &#8221; Hi! &#8220;, you recive immediately an error which says: <em><strong>Error</strong>: You must complete age verification process to communicate with this member. Click here to verify your age!</em></p>
<p style="text-align:center;"><em><a href="http://antelox.files.wordpress.com/2010/05/page2.jpg" target="_blank"><img class="aligncenter size-medium wp-image-98" title="Page2" src="http://antelox.files.wordpress.com/2010/05/page2.jpg?w=300&#038;h=152" alt="" width="300" height="152" /></a><br />
</em></p>
<p>The link &#8220;Click here to verify your age!&#8221; acts as a fake age verify, because it serves to <em>accept the invite</em></p>
<p style="text-align:center;"><a href="http://antelox.files.wordpress.com/2010/05/fake.jpg" target="_blank"><img class="aligncenter size-medium wp-image-99" title="Fake" src="http://antelox.files.wordpress.com/2010/05/fake.jpg?w=300&#038;h=152" alt="" width="300" height="152" /></a></p>
<p>infact clicking it we&#8217;ll redirect to this page:</p>
<p style="text-align:center;"><a href="http://antelox.files.wordpress.com/2010/05/second1.jpg" target="_blank"><img class="aligncenter size-medium wp-image-100" title="second" src="http://antelox.files.wordpress.com/2010/05/second1.jpg?w=300&#038;h=124" alt="" width="300" height="124" /></a></p>
<p>Scroll down and you can see a classic registation form, which asks you Name, Surname, E-Mail, etc&#8230;</p>
<p style="text-align:center;"><a href="http://antelox.files.wordpress.com/2010/05/registration.jpg" target="_blank"><img class="aligncenter size-medium wp-image-101" title="Registration" src="http://antelox.files.wordpress.com/2010/05/registration.jpg?w=300&#038;h=152" alt="" width="300" height="152" /></a></p>
<p style="text-align:left;">Here the screenshot regards the credit fraud:</p>
<p style="text-align:left;"><a href="http://antelox.files.wordpress.com/2010/05/fraud.jpg" target="_blank"><img class="aligncenter size-medium wp-image-102" title="Fraud" src="http://antelox.files.wordpress.com/2010/05/fraud.jpg?w=300&#038;h=187" alt="" width="300" height="187" /></a></p>
<p>So friends, this is all! Block and delete this address and similar!</p>
<p>See you in the next post. Bye. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/93/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=93&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/05/30/just-another-msns-fake-address-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/form.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/05/page1.jpg?w=300" medium="image">
			<media:title type="html">Page</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/page2.jpg?w=300" medium="image">
			<media:title type="html">Page2</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/fake.jpg?w=300" medium="image">
			<media:title type="html">Fake</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/second1.jpg?w=300" medium="image">
			<media:title type="html">second</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/registration.jpg?w=300" medium="image">
			<media:title type="html">Registration</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/fraud.jpg?w=300" medium="image">
			<media:title type="html">Fraud</media:title>
		</media:content>
	</item>
		<item>
		<title>A brief analysis about Trojan.Banker.Delf.ZLR</title>
		<link>http://antelox.wordpress.com/2010/05/22/a-brief-analysis-about-trojan-banker-delf-zlr/</link>
		<comments>http://antelox.wordpress.com/2010/05/22/a-brief-analysis-about-trojan-banker-delf-zlr/#comments</comments>
		<pubDate>Sat, 22 May 2010 09:15:29 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Malware Analysis]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=76</guid>
		<description><![CDATA[Hi to all! Today I will speak very briefly about a new threat that affects banks. Specifically the Brazilian bank Bradesco [hxxp://www.bradesco.com.br/]. Some info about the Bradesco Bank: Type: Public (BM&#38;F Bovespa:BBDC3 / BBDC4 NYSE: BBD BMAD: XXBDC) Industry: Finance and Insurance Founded: 1943 Headquarters: Osasco, Brazil Key people: Luiz Carlos Trabuco Cappi (CEO) Lázaro [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=76&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hi to all!</p>
<p>Today I will speak very briefly about a new threat that affects banks. Specifically the Brazilian bank <strong>Bradesco</strong> [hxxp://www.bradesco.com.br/]. </p>
<p>Some info about the Bradesco Bank:</p>
<p><code><br />
<code><strong>Type</strong>:                        Public (BM&amp;F Bovespa:BBDC3 / BBDC4 NYSE: BBD BMAD: XXBDC)</code></p>
<p><code><strong>Industry</strong>: 	                Finance and Insurance</code></p>
<p><code><strong>Founded</strong>: 	                1943</code></p>
<p><code><strong>Headquarters</strong>: 	        Osasco, Brazil</code></p>
<p><code><strong>Key people</strong>: 	        Luiz Carlos Trabuco Cappi (CEO)  Lázaro de Mello Brandão (Chairman of the Board of Directors) Antônio Bornia (Vice-Chairman of the Board of Directors)</code></p>
<p><code><strong>Products</strong>: 	                Banking</code></p>
<p><code><strong>Revenue</strong>: 	                ▲US$ 36.1 Billion (2009)</code></p>
<p><code><strong>Net income</strong>: 	        ▲US$ 4.5 Billion (2009)</code></p>
<p><code><strong>Total assets</strong>: 	        ▲US$ 299.0 Billion (2010)</code></p>
<p><code><strong>Employees</strong>:              	85,577</code><br />
</code></p>
<p>The Trojan banker in question is called, in according to the nomenclature of the antivirus houses; <strong>Trojan.Banker.Delf.ZLR</strong>.</p>
<p>Before I start talking about what makes the virus, I give you some general information about the target, such as: the geometry of the PE format, any packer/compressed/Cryptor, etc&#8230;</p>
<p>The threat, at the time of this writing, is recognized by <em>15/41</em> AV as suggested by VirusTotal.</p>
<p>Hash MD5: <strong>fc3f089f7d64eb4dcc7113c5add3bda7</strong></p>
<p>Hash SHA-1: <strong>ae521a311bde3667d7bcb74460b4a6e92a8cd2c8</strong></p>
<p>Imports:</p>
<p><strong>advapi32.dll</p>
<p>comctl32.dll</p>
<p>gdi32.dll</p>
<p>kernel32.dll</p>
<p>oleaut32.dll</p>
<p>user32.dll</p>
<p>version.dll</strong></p>
<p>Sections:</p>
<p><strong>UPX0</p>
<p>UPX1</p>
<p>.rsrc</strong></p>
<p>There is also the presence of <strong>TLS Directory</strong>, so if anyone wants to analyze this virus more in depth must keep in mind to ensure that, going to make a dynamic analysis through a debugger like OllyDbg need to configure the debugger so that it stops before the <em>TLS Callback</em> to prevent any action that the virus anticipates before it goes to the OEP.</p>
<p>It&#8217;s easy to understand that the file is packed with the very common free compressor UPX. Since it is so let&#8217;s go to decompress it. I did through the splendid suite of Ntoskrnl <strong>Explorer Suite</strong> which also includes a UPX utility for this purpose. </p>
<p>Immediately after decompressed the file, analyzing it with a PE Scanner, such as PEiD or RDG Packer Detector, and we note that is written in <em>Delphi</em>. Another info which is very helpfull in most cases but not in this specific sample. In Malware Analysis more info we can get from target study and much easier is to analyze our target.</p>
<p>As I already said, this virus is one of those classics that tries to steal the credentials of the bank accounts of the poor unfortunate. That&#8217;s why they are called Trojans Banker <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> . Trojan.Banker.Delf.ZLR essentially does nothing special. Basically is a <em>fake program</em> was created specifically to belive you need to perform banking transactions directly from your PC.</p>
<p>It consists of a classical form which contains 3 special edit for entering your bank account and a way to &#8220;<em>simulate</em>&#8221; the installation of this false account management program. But let&#8217;s go to see how it is made:</p>
<p><img src="http://antelox.files.wordpress.com/2010/05/first.jpg?w=450" alt="" /></p>
<p>When the victim had entered the bank account details, click on &#8220;<strong>Instalar</strong>&#8221; notice that will be simulated to download a dll. I say <em>simulated</em> because it actually does not download any dll, as you can check by running Wireshark while performing these steps, which shows no <em>GET request</em> from any site, but also going to search for the name <strong>ib2k1.dll</strong> find anything on the system. All this is done only to make the installation process look better.</p>
<p><img src="http://antelox.files.wordpress.com/2010/05/second.jpg?w=450" alt="" /></p>
<p>Simulated the download of this dll, we get the form to enter your account credentials, such as the account holder, password and secret word. This is then sent to the site who created the fake program to steal these credentials.<br />
Between the strings contained by the file I found very interesting two particular things: a URL and a sentence, respectively,</p>
<p><strong>http://firefoxxx.t35.com/Dario.envio.desco.php</strong></p>
<p><strong>Bradesco by D4RiO</strong></p>
<p>What we understand is that he who created the software is called <em>Dario</em> and the URL that contact is: <em>http://firefoxxx.t35.com/Dario.envio.desco.php</em></p>
<p>Here a screenshot about:</p>
<p><img src="http://antelox.files.wordpress.com/2010/05/third.jpg?w=450" alt="" /></p>
<p>Then we come to form of the credit card owner. In this form must be included the last <em>three digits of its Credit Card Number</em> and press <em>Confirm</em> to send everything that was stored by the program to the URL mentioned above.</p>
<p><img src="http://antelox.files.wordpress.com/2010/05/fourth.jpg?w=450" alt="" /></p>
<p>For this time it&#8217;s all guys. See you at the next post. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/76/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/76/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/76/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=76&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/05/22/a-brief-analysis-about-trojan-banker-delf-zlr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>

		<media:content url="http://antelox.files.wordpress.com/2010/05/first.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/05/second.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/05/third.jpg" medium="image" />

		<media:content url="http://antelox.files.wordpress.com/2010/05/fourth.jpg" medium="image" />
	</item>
		<item>
		<title>Other fake MSN&#8217;s address</title>
		<link>http://antelox.wordpress.com/2010/04/09/other-fake-msns-address/</link>
		<comments>http://antelox.wordpress.com/2010/04/09/other-fake-msns-address/#comments</comments>
		<pubDate>Fri, 09 Apr 2010 19:43:28 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=60</guid>
		<description><![CDATA[Hi, I discovered other fake MSN&#8217;s address. There isn&#8217;t much to say because they are similar to the previous fake address. I will only tell you the address and their malicious site respectively. margaretekuter24@hotmail.com &#8211;&#62; http://www.freecamlink.net/a2vhj &#8211;&#62; redirect to http://webcammunitylive.com/?i=fec3e5eea65247c then &#8211;&#62; http://webcammunity.com/cam/danielahot1/?AFNO=1-490 romabjorkman64@hotmail.com &#8211;&#62; http://www.freecamlink.net/a2vqg &#8211;&#62; redirect to http://webcammunitylive.com/?i=fec3e5eea65247c then &#8211;&#62; http://webcammunity.com/cam/Karlla/?AFNO=1-490 lavetakettinger70@hotmail.com &#8211;&#62; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=60&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hi,<br />
I discovered other fake MSN&#8217;s address. There isn&#8217;t much to say because they are similar to the previous fake address. I will only tell you the address and their malicious site respectively.</p>
<p><strong>margaretekuter24@hotmail.com</strong>  &#8211;&gt;<br />
<em>http://www.freecamlink.net/a2vhj</em>  &#8211;&gt; redirect to<br />
<em>http://webcammunitylive.com/?i=fec3e5eea65247c</em>  then  &#8211;&gt;<br />
<em>http://webcammunity.com/cam/danielahot1/?AFNO=1-490</em></p>
<p><strong>romabjorkman64@hotmail.com</strong>  &#8211;&gt;<br />
<em>http://www.freecamlink.net/a2vqg</em>  &#8211;&gt;  redirect to<br />
<em>http://webcammunitylive.com/?i=fec3e5eea65247c</em> then  &#8211;&gt;<br />
<em>http://webcammunity.com/cam/Karlla/?AFNO=1-490</em></p>
<p><strong>lavetakettinger70@hotmail.com</strong> &#8211;&gt;<br />
<em>http://www.freecamlink.net/a2vpj</em> &#8211;&gt;  redirect to<br />
<em>http://webcammunitylive.com/?i=fec3e5eea65247c</em>  then &#8211;&gt;<br />
<em>http://webcammunity.com/cam/StrikingEyes/?AFNO=1-490</em></p>
<p><strong>grazynaamistadi97@hotmail.com</strong>  &#8211;&gt;<br />
<em>http://www.freecamlink.net/a8n6r</em> redirect to  &#8211;&gt;<br />
<em>http://webcammunitylive.com/?i=c97edfdd517d54a</em>  then  &#8211;&gt;<br />
<em>http://webcammunity.com/cam/Margie/?AFNO=1-497</em></p>
<p>Only one thing, the third url is always changing each time that you visit the first link. It redirect always to different girls. <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Bye, see you to the next post. =)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=60&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/04/09/other-fake-msns-address/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>
	</item>
		<item>
		<title>ARM Opcode</title>
		<link>http://antelox.wordpress.com/2010/03/21/arm-opcode/</link>
		<comments>http://antelox.wordpress.com/2010/03/21/arm-opcode/#comments</comments>
		<pubDate>Sun, 21 Mar 2010 23:19:59 +0000</pubDate>
		<dc:creator>Antelox</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://antelox.wordpress.com/?p=57</guid>
		<description><![CDATA[Strong ARM (SA1110) Opcodes Command Hex Example &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; B xxxxxxEA branch BEQ xxxxxx0A b if zero (Z) BNE xxxxxx1A b if not equal (-Z) BGE xxxxxxAA b if greater or equal (N*V/-N*-V) BHI xxxxxx8A b if higher (-C*-Z) BLT xxxxxxBA b if less than (N*-V/-N*V) BCC xxxxxx3A b if carry clear BCS xxxxxx2A b if [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=57&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Strong ARM (SA1110) Opcodes</p>
<p>Command Hex Example<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
B xxxxxxEA branch<br />
BEQ xxxxxx0A b if zero (Z)<br />
BNE xxxxxx1A b if not equal (-Z)<br />
BGE xxxxxxAA b if greater or equal (N*V/-N*-V)<br />
BHI xxxxxx8A b if higher (-C*-Z)<br />
BLT xxxxxxBA b if less than (N*-V/-N*V)<br />
BCC xxxxxx3A b if carry clear<br />
BCS xxxxxx2A b if carry set<br />
BVC .<br />
BVS .<br />
BPL xxxxxx5A<br />
BMI xxxxxx4A b if negative, set N<br />
BHS .<br />
BLO .<br />
BLS xxxxxx9A b if lower or same (C/Z)<br />
BGT xxxxxxCA b if greater than (N*V*-Z/-N*-V*-Z)<br />
BLE xxxxxxDA b if less or equal (Z/N*-V/-N*V)</p>
<p>00022714 B loc_22734 06 00 00 EA<br />
000226B8 BLE loc_226E4 09 00 00 DA</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>BL xxxx00EB<br />
BLEQ xxxx000B</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>MOV (reg,value) xxxxA0E3 Mov R1,#0 0010A0E3<br />
Mov R0,#1 0100A0E3<br />
MOVEQ (reg,value) xxxxA003 Moveq R5, #0 0050A003<br />
MOVNE (reg,value) xxxxA013<br />
MOVGE (reg,value) xxxxA0A3<br />
MOVHI (reg,value) xxxxA083</p>
<p>7F 0C A0 E3 MOV R0, #0x7F00<br />
27 3B A0 E3 MOV R3, #0x9C00</p>
<p>value = erste 2 bytes * mX (x = Byte 4)</p>
<p>m1 := $40000000;<br />
m2 := $10000000;<br />
m3 := $4000000;<br />
m4 := $1000000;<br />
m5 := $400000;<br />
m6 := $100000;<br />
m7 := $40000;<br />
m8 := $10000;<br />
m9 := $4000;<br />
mA := $1000;<br />
mB := $400;<br />
mC := $100;<br />
mD := $40;<br />
mE := $10;<br />
mF := $4;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>MOV (reg,reg) xxxxA0E1 Mov R4,R0 0040A0E1<br />
Mov R7,R1 0170A0E1<br />
MOVEQ (reg,reg) xxxxA001<br />
MOVNE (reg,reg) xxxxA011</p>
<p>00 38 A0 E1 MOV R3, R0,LSL#16<br />
23 38 A0 E1 MOV R3, R3,LSR#16</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>MOVS R10, R11,ASR#31 CB AF B0 E1<br />
MOVS R11, R1,ASR#31 C1 BF B0 E1</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>CMP (reg,val) 00 00 53 E3<br />
CMP R0,#0 00 00 50 E3<br />
CMP R5,#0 00 00 55 E3<br />
CMPEQ R3,#1 01 00 53 03</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>CMP (reg,reg) xx xx 5X E1<br />
CMP R0,R3 03 00 50 E1</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>LDR R0,[R1,#0x38] 38 00 91 E5<br />
LDR R0,[R5] 00 00 95 E5<br />
LDR R2, [R3] 00 20 93 E5<br />
LDR R1, [R6] 00 10 96 E5</p>
<p>LDRB R2,[R0,#2] 02 20 D0 E5</p>
<p>LDRSH R1, [R6,#0x54] F4 15 D6 E1<br />
LDRSH R1, [R6,#0x56] F6 15 D6 E1</p>
<p>LDRSB R3, [SP,#2] D2 30 DD E1</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>STR R0,[R7] 00 00 87 E5</p>
<p>STRB R1,[R0,R3] 03 10 C0 E7<br />
STRB R11,[LR] 00 B0 CE E5<br />
STRB R11,[LR,#1] 01 B0 CE E5</p>
<p>STRH R3, [R4,#0xC] BC 30 C4 E1<br />
STRH R3, [R4,#0xE] BE 30 C4 E1<br />
STRH R3, [R1] B0 30 C1 E1</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>ORR R3,R3,#0xC 0C 30 83 E3<br />
ORR R3,R3,#0x3C 3C 30 83 E3<br />
ORRS R1, R1, #0&#215;80 80 10 91 E3<br />
ORRS R3, R2, R3,LSL#8 03 34 92 E1<br />
ORRS R5, R2, R3,LSL#8 03 54 92 E1</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>ADD R3, R2, R3 03 30 82 E0<br />
ADD R2, R2, #1 01 20 82 E2<br />
ADD R1, R1, #4 04 10 81 E2<br />
ADD SP, SP, #4 04 D0 8D E2</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>SUB SP, SP, #0&#215;38 38 D0 4D E2<br />
SUB R3, R11, R0 00 30 4B E0</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>ANDS R3, R10, #0xFF FF 30 1A E2<br />
ANDS R3, R0, #0xFF FF 30 10 E2</p>
<p>AND R10, R9, R10 0A A0 09 E0<br />
AND R10, R4, R10 0A A0 04 E0<br />
AND R11, R11, #0xF8 F8 B0 0B E2</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>MUL R11, R2, R4 92 04 0B E0<br />
MUL R9, R11, R3 9B 03 09 E0<br />
MUL R0, R2, R0 92 00 00 E0</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>RSBMI R10, R1, #0 00 A0 61 42<br />
RSBGT R6, R1, R4 04 60 61 C0<br />
RSBMI R4, R2, #0 00 40 62 42</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>RET 0EF0A0E1</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Virtual NOP MOV R0, R0 00 00 A0 E1</p>
<p>LDREQ R3, [R7,#0x10] = 10 30 97 05<br />
LDREQ R0, [R3,#0x8] = 08 00 93 05</p>
<p>From <em>Fravia</em>&#8216;s site.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/antelox.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/antelox.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/antelox.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/antelox.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/antelox.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/antelox.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/antelox.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/antelox.wordpress.com/57/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=antelox.wordpress.com&amp;blog=9077882&amp;post=57&amp;subd=antelox&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://antelox.wordpress.com/2010/03/21/arm-opcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7ab1ddeacb42b71dee6f9b2fc46ae412?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Antelox</media:title>
		</media:content>
	</item>
	</channel>
</rss>
