[DiscordArchive] what if that was just a build where their tool failed to properly process the game exe and they aren
[DiscordArchive] what if that was just a build where their tool failed to properly process the game exe and they aren
Archived author: Tea • Posted: 2024-06-26T13:47:17.796000+00:00
Original source
what if that was just a build where their tool failed to properly process the game exe and they arent cooking up anything new?
Archived author: Fabian • Posted: 2024-06-26T13:47:25.403000+00:00
Original source
they do
Archived author: Fabian • Posted: 2024-06-26T13:47:37.964000+00:00
Original source
overwatch_loader.dll tells us (which was also required to run the game)
Archived author: Fabian • Posted: 2024-06-26T13:47:38.695000+00:00
Original source
Archived author: Fabian • Posted: 2024-06-26T13:47:56.252000+00:00
Original source
which actually has some opaque predicates and very big jump tables <:lul:451485508380655616>
Archived author: _mrfade_ • Posted: 2024-06-26T14:29:45.755000+00:00
Original source
Ye I've just thrown together a simple ida script for this but thanks for the share never the less lol.
deobfuscating the flow isn't really my main concern at the moment it's more so locating the scans in memory, think I am just gonna spin up a vm and try kernel debug it ♂️