Writing a Mutation Engine and Breaking Aimware(back.engineering) |
Writing a Mutation Engine and Breaking Aimware(back.engineering) |
In 1993 the virus group Phalcon/Skism from Canada published a polymorphic engine called Dark Angel's Multiple Encryptor or DAME, the writeup of that is still available:
https://ivanlef0u.fr/repo/madchat/vxdevl/vdat/tuda0011.htm
That inspired me to do similar things, playing around with replacing bits of assembly with functionally equivalent alternatives, and using differing encoding of common instructions.
Of course all of this is very obsolete knowledge these days, which is a shame in some ways.
https://news.ycombinator.com/item?id=30941097
So maybe I was wrong, this kind of experimentation and knowledge is still useful.