Entry-Point Obfuscation (Stolen Bytes)
The packer copies the original entry point's first instructions into dynamically allocated stub memory and redirects the EP, so a naive dump lacks those bytes and the real OEP stays hidden until they are recovered.
"Stolen bytes" is an anti-dump trick that splits the original entry point. Instead of unpacking the program and jumping cleanly to its real OEP, the packer copies the OEP's first few instructions into a freshly allocated buffer, executes them there, and only then jumps into the body of the original code at OEP+N. A dump taken after unpacking has correct code from OEP+N onward but a hole where the first instructions used to be, and the entry point in the dumped header still points at the packer stub, so the rebuilt binary crashes immediately on launch.
How it works
The packer lifts the leading bytes at OEP, relocates them into stub memory, and resumes execution mid-function:
; --- in the stub's allocated buffer (the "stolen" prologue) ---
stolen:
push ebp ; bytes copied verbatim from the real OEP
mov ebp, esp
sub esp, 0x40
jmp 0x00401016 ; jump back into the original code at OEP + N
; --- on disk at the real OEP these bytes are now zeroed or junk ---
0x00401010: 00 00 00 00 00 00 ; the prologue is gone from the imageThe header's AddressOfEntryPoint is set to the stub, never to 0x00401010, so even locating OEP visually is non-obvious.
Detection & bypass
- Static —
AddressOfEntryPointlands in a writable/high-entropy section rather than.text. The bytes at the apparent code start are zeroed or nonsensical, and there is no clean function prologue at the image base + a plausible offset. - Dynamic — Find the true OEP: run-until-tail-jump, the ESP trick (hardware breakpoint on the stack value the unpacker restores), or Scylla's OEP Finder. When execution reaches the stub prologue you will see a handful of "free-floating" instructions in allocated memory ending in a
jmpback into.text— that jump's target is OEP+N, and the instructions above it are the stolen bytes. - Rebuild — Recover the stolen prologue from the stub buffer (copy the exact bytes executed before the jump). In the dump, write those bytes back at the real OEP and set
AddressOfEntryPointto that OEP so the prologue and body are contiguous again. Then dump with Scylla, fix the IAT, and validate that the entry now begins with a real prologue. - Tools — x64dbg (tracing, hardware breakpoints, Scylla OEP Finder), Scylla (dump + EP fix), and manual reconstruction in PE-bear to patch the stolen bytes and entry point.