IP Library › Granted Patent US 10,261,783
Granted Patent B2
US 10,261,783 · App. 15/150,046 · Granted Apr 16, 2019

Automated unpacking of portable executable files

Inventor: Tomislav Pericin (Sremska Mitrovica, RS)
Assignee: Reversing Labs Holding GmbH
G06F8/74G06F8/65G06F11/0715G06F11/0721G06F11/0751G06F11/0793G06F11/362
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,261,783
App. No.
15/150,046
Granted
Apr 16, 2019
Kind
B2
Abstract

Automated unpacking of a portable executable file includes setting a debugging breakpoint at an original entry point address of a packed portable executable file. A debugging process is executed for the packed portable executable file to obtain a debugged portable executable file in memory. One or more of import address table data and relocation table data are collected during execution of the debugging process for the packed portable executable file. The debugged portable executable file in memory is copied to a storage medium, and the debugging process is terminated.

Claims (45)

1. A computer implemented method comprising:

setting, by a computing device, a debugging breakpoint at an original entry point address of a packed portable executable file;

executing, by the computing device, a debugging process for the packed portable executable file to obtain a debugged portable executable file;

adding a new section to the debugged portable executable file;

pasting into the debugged portable executable file in the new section one or more of an import address table of the import table data and a relocation table of the relocation table data collected during execution of the debugging process for the packed portable executable file;

realigning the debugged portable executable file by, at least in part, compacting the debugged portable executable file and verifying that the debugged portable executable file is a valid image; and

creating a valid portable executable file.

2. The computer implemented method of claim 1 , further comprising determining, by the computing device, the original entry point address of the packed portable executable file based upon, at least in part, ImageBase field data of the packed portable executable file and AddressOfEntryPoint data of the packed portable executable file.

3. The computer implemented method of claim 1 , further comprising initializing, by the computing device, the debugging process including creating a debugging process based upon, at least in part, the packed portable executable file.

4. The computer implemented method of claim 1 , wherein the original entry point includes a first instruction of executable code before the packed portable executable file was protected.

5. The computer implemented method of claim 1 , further comprising collecting, by the computing device, one or more of import address table data and relocation table data during execution of the debugging process for the packed portable executable file by setting one or more debugging breakpoints associated with a LoadLibrary call, a GetModuleHandle call, and each of a plurality of GetProcAddress calls.

6. The computer implemented method of claim 1 , further comprising:

copying, by the computing device, the debugged portable executable file in memory to a storage medium; and

terminating, by the computing device, the debugging process at the original entry point.

7. A computer program product comprising a non-transitory computer readable medium having a plurality of instructions stored thereon, which, when executed by a processor, cause the processor to perform operations comprising:

setting a debugging breakpoint at an original entry point address of a packed portable executable file;

executing a debugging process for the packed portable executable file to obtain a debugged portable executable file;

adding a new section to the debugged portable executable file;

pasting into the debugged portable executable file in the new section one or more of an import address table of the import table data and a relocation table of the relocation table data collected during execution of the debugging process for the packed portable executable file;

realigning the debugged portable executable file by, at least in part, compacting the debugged portable executable file and verifying that the debugged portable executable file is a valid image; and

creating a valid portable executable file.

8. The computer program product of claim 7 , further comprising instructions for determining the original entry point address of the packed portable executable file based upon, at least in part, ImageBase field data of the packed portable executable file and AddressOfEntryPoint data of the packed portable executable file.

9. The computer program product of claim 7 , further comprising instructions for initializing the debugging process including creating a debugging process based upon, at least in part, the packed portable executable file.

10. The computer program product of claim 7 , wherein the original entry point includes a first instruction of executable code before the packed portable executable file was protected.

11. The computer program product of claim 7 , further comprising instructions for collecting one or more of import address table data and relocation table data during execution of the debugging process for the packed portable executable file by setting one or more debugging breakpoints associated with a LoadLibrary call, a GetModuleHandle call, and each of a plurality of GetProcAddress calls.

12. The computer program product of claim 7 , further comprising instructions for:

copying the debugged portable executable file in memory to a storage medium; and

terminating the debugging process at the original entry point.

13. A system comprising:

a processor;

a memory coupled with the processor;

one or more software modules executable by the processor and the memory, the one or more software modules, when executed, configured to perform operations including:

setting a debugging breakpoint at an original entry point address of a packed portable executable file;

executing a debugging process for the packed portable executable file to obtain a debugged portable executable file;

adding a new section to the debugged portable executable file;

pasting into the debugged portable executable file in the new section one or more of an import address table of the import table data and a relocation table of the relocation table data collected during execution of the debugging process for the packed portable executable file;

realigning the debugged portable executable file by, at least in part, compacting the debugged portable executable file and verifying that the debugged portable executable file is a valid image; and

creating a valid portable executable file.

14. The system of claim 13 , wherein the one or more software modules are further configured to determine the original entry point address of the packed portable executable file based upon, at least in part, ImageBase field data of the packed portable executable file and AddressOfEntryPoint data of the packed portable executable file.

15. The system of claim 13 , wherein the one or more software modules are further configured to initialize the debugging process including creating a debugging process based upon, at least in part, the packed portable executable file.

16. The system of claim 13 , wherein the original entry point includes a first instruction of executable code before the packed portable executable file was protected.

17. The system of claim 13 , wherein the one or more software modules are further configured to collect one or more of import address table data and relocation table data during execution of the debugging process for the packed portable executable file by setting one or more debugging breakpoints associated with a LoadLibrary call, a GetModuleHandle call, and each of a plurality of GetProcAddress calls.

18. The system of claim 13 , wherein the one or more software modules are further configured to:

copy the debugged portable executable file in memory to a storage medium; and

terminate the debugging process at the original entry point.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2024
From: REVERSING LABS HOLDING GMBH
To: REVERSING LABS INTERNATIONAL GMBH
Reel/Frame 068350/0701 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2016
From: PERICIN, TOMISLAV
To: REVERSING LABS HOLDING GMBH
Reel/Frame 038644/0521 →
Continuity (3)
Continuation 12846044 · Jul 29, 2010
Provisional Application 61229497 · Jul 29, 2009
Related Publication 20160253253A1 · Sep 1, 2016