文章目录
-
- 1.导入导出基本信息获取
- 2.界面分析
- 3.X64dbg分析
- 4.条件日志打印
- 5.命令表达式
- 6.X64dbg PS脚本
1.导入导出基本信息获取
打开windows控制台,然后输入如下命令:
dumpbin /IMPORTS SeparationPreview.aip #查看导入函数列表
dumpbin /DEPENDENTS SeparationPreview.aip #查看导入dll
导入dll如下所示:
SPBasic.dll
dvacore.dll
dvaui.dll
dvaai.dll
boost_system.dll
MSVCP140.dll
VCRUNTIME140.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-time-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-filesystem-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-math-l1-1-0
