logoalt Hacker News

sedatktoday at 2:19 AM3 repliesview on HN

They're not encoded, but the code blocks are shuffled. That's why disassembly does look straightforward, but it used to thwart BinDiff at the time.


Replies

shaknatoday at 12:41 PM

That sounds a lot like US9116712, but I don't think its ever been publicly said that Windows does this.

j16sdiztoday at 5:35 AM

If I understand correctly, that is just randomness comes from parallel compiling and linking.

If you saying there is a whole step just scrambling blobs, i will be very surprised.

dataflowtoday at 3:16 AM

What made you believe this is the case? any examples/links/etc.?

show 1 reply