Answer Page
The direct answer for this is simple
Answer
There were many things that made it easy to identify and analyze the routines. The best of all was the fact that the import table was not stripped and it was pretty easy to locate network/localconnection based API calls using basic documentation.
Last updated
