[spam][crazy] bomb malware

Karl gmkarl at gmail.com
Tue Dec 14 03:02:59 PST 2021


I didn't end up including comments.

the LAB_* references pushed onto the stack (to be passed to
FUN_0804d23f) are function pointers.  I click on them or hit enter
while over them and end up hitting 'F' to reanalyse them as functions.
I can tell they are functions because the instructions at their start
and end are always used for functions.

in ida pro you hit 'esc' to return to where you just were, in ghidra
it's alt-shift-left


More information about the cypherpunks mailing list