Jump to content
Tuts 4 You

All Activity

This stream auto-updates

  1. Past hour
  2. vinod123

    Revteam Reverse Engineering Collection

    here are the files/folders of 'Zero2Automated revteam.rar'
  3. Today
  4. motaghred

    The Enigma Protector v7.70 (x32 & x64)

    can someone upload ways (tut )how bypassing Antidebug and bypass HWID and PASSWORD ?
  5. azufo

    The Enigma Protector v7.70 (x32 & x64)

    rc4 keyanti-hijacking won't work by adding a new my section and a new import but I won't upload it for you to study sry...
  6. lengyue

    The Enigma Protector v7.70 (x32 & x64)

    add AntiPatchHWID,Antidebug ,Antidllhijack.
  7. azufo

    The Enigma Protector v7.70 (x32 & x64)

    here not new only add one debug flag that is all rsa
  8. lengyue

    The Enigma Protector v7.70 (x32 & x64)

    The Enigma Protector_7.7 Protection End Version.The final version has been released, and I will not update it for a long time thereafter. Welcome to complete the challenge. https://workupload.com/file/fNbFuNZgSKG The Enigma Protector_7.7 Protection End Version.rar
  9. A.S.L

    Exeinfo PE

    0.0.8.7 Beta II ExeinfoPe_0087_Beta_II.zip
  10. lengyue

    The Enigma Protector v7.70 (x32 & x64)

    I use AntiPatchHWID, ordinary users even if they find the real machine code, should not be able to PatchHWID. Of course, meet such a master like you, a different matter, no one can stop your footsteps.
  11. lengyue

    The Enigma Protector v7.70 (x32 & x64)

    Yes, this is very interesting. Hello, Sir. It seems I can't hold you back. The public key is not found in the original program. Mr. Azufo used a special technique to pull it off.
  12. Yesterday
  13. TRISTAN Pro

    The Enigma Protector v7.70 (x32 & x64)

    I find this in the app but how to use this in keygen? I have app to challenge yuo if yuo want check it.
  14. azufo

    The Enigma Protector v7.70 (x32 & x64)

    This is not true, very easy to find constant encription and yea here again find easy for create keygen but no need this
  15. azufo

    The Enigma Protector v7.70 (x32 & x64)

    U use again some cheap trick heree but , u know result ..... Keep in mind that I cracked the latest dongles Guardant,Senselock and etc. this will that stop me? name: Mr.Leng key:B4HMR2CA76ACVESM2CL7A7X355RQ63RLGYYVW5VYEV48FWGJ8DZRJ44C78SFN3FF9PPF6UBUERAKCJUY9YJXGT3DXB9JX78A39YLBHUFUDGT @lengyue real hwid is here other vmp instruction u are add here on this target are bullshit rva:451904 Enigma shutdown.rar
  16. letsphonk

    Revteam Reverse Engineering Collection

    Is the "Zero2Automated RevTeam" course folder complete? I couldn't find any chapters beyond Chapter 4. Thanks for sharing
  17. Sh4DoVV

    The Enigma Protector v7.70 (x32 & x64)

    Good target , Used custom plugin ?
  18. Last week
  19. lengyue

    The Enigma Protector v7.70 (x32 & x64)

    I took the time to do another example to enhance it a bit. If you are free and interested, you can test the strength. https://workupload.com/file/KLCrS6REwxR
  20. idrcelab

    Another Simple Loader(Delphi SRC)

    Anyone have a copy of this article? It need to sign up first. Thank you
  21. Sean Park - Lovejoy

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    @TRISTAN Pro Can you please upload your script in here? Regards. sean.
  22. TRISTAN Pro

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    It's the same as old just use my script everything will work but need fix the target after unpacked. @Sean Park - Lovejoy check in this forum.
  23. Sean Park - Lovejoy

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    @boot Do we have to unwrap wrapped apis one by one manually? Regards. sean.
  24. Bang1338

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    g++ compiler somehow hate winlicense sdk...
  25. boot

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    Can you upload a sample that locked HWID?
  26. TitanHide doesn't work from version 3.9.1 without debugger detect !
  27. Earlier
  28. Sean Park - Lovejoy

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    How Is WinAPI Emulation Different from Themida’s Advanced API Wrapping? While both techniques protect API calls, they operate differently: Feature WinAPI Emulation (Enigma) Advanced API Wrapping (Themida) Method Replaces API calls with emulated versions Adds a wrapper layer around API calls Behavior Emulates API logic internally Calls the real API through an obfuscated wrapper Focus Protects execution by hiding actual APIs Focuses on obfuscating API invocation and flow Complexity May not use the real API at all Always eventually calls the real API Differences Between WinAPI Redirect and WinAPI Emulation Feature WinAPI Redirect WinAPI Emulation Core Function Redirects API calls to custom or protected logic Fully replaces API calls with an internal implementation Interaction with Real API Often forwards calls to the real API (after processing) May not interact with the real API at all Customization Allows developers to define specific behaviors Behaves more like a controlled "sandbox" for API calls Primary Use Case Controlling or filtering API behavior Obfuscating or hiding API logic Regards. sean.
  29. Sean Park - Lovejoy

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    @boot How to unwrap wrapped apis? Regards. sean.
  30. Sean Park - Lovejoy

    TinyCrackMe - WinLicense 3.1.7.0 Edition

    Themida’s Advanced API Wrapping doesn’t mean using different APIs to make a call but rather involves wrapping and obfuscating existing API calls to make them more difficult to analyze, intercept, or manipulate by attackers. Here's a detailed explanation: What Happens with Advanced API Wrapping? Interception and Wrapping: Themida intercepts standard API calls made by your program (e.g., calls to Windows APIs or libraries) and replaces them with custom “wrapped” versions. These wrapped versions act as intermediaries between the application and the actual API. Obfuscation of Parameters and Flow: Parameters passed to the API can be encoded, encrypted, or altered by the wrapper. The wrapper logic itself is obfuscated, making it difficult for an attacker to understand how the API call is being processed or what arguments are being passed. Redirection and Layering: Calls may be redirected through additional layers of code or custom logic before reaching the actual API. These layers might perform security checks (e.g., anti-debugging, anti-tamper) or simply add noise to confuse reverse engineers. Dynamic Behavior: The wrapper might dynamically adjust how it interacts with the API based on runtime conditions, making static analysis tools ineffective. For example, some wrapped API calls may only function correctly in a valid execution environment, preventing sandboxed analysis. What This Means for API Calls Obfuscation: While the actual API (e.g., CreateFile or ReadProcessMemory) remains the same, the way it is invoked appears obfuscated due to the added wrapper logic. Attackers analyzing the program won't see straightforward API calls. Instead, they'll encounter a chain of custom function calls or complex operations obscuring the original API call. Security Checks: The wrapper might add security checks (e.g., validating the environment) before deciding whether to allow the API call to proceed. Anti-Hooking: By wrapping API calls, Themida makes it harder for attackers to use hooking techniques to monitor or modify API calls, as they can't directly intercept the standard APIs. What Advanced API Wrapping Does NOT Mean Using Different APIs: It doesn't replace one API with another (e.g., using OpenFile instead of CreateFile); rather, it modifies how the original API call is invoked and processed. Changing API Functionality: The underlying functionality of the API remains the same; the changes are in how the application interacts with it. Example (Simplified) Consider a program that calls CreateFile. Without Themida, it might look like this in pseudo-code: c Copy code HANDLE fileHandle = CreateFile("example.txt", GENERIC_READ, 0, NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL); With Themida's API Wrapping, this might become: c Copy code HANDLE fileHandle = Wrapped_API_XYZ_123("encoded_example.txt", obfuscated_flags, security_token); Obfuscated Call: Instead of calling CreateFile directly, it goes through Wrapped_API_XYZ_123, which contains complex and obfuscated logic. Encoded/Encrypted Parameters: The string "example.txt" and other arguments might be encoded or encrypted before being passed to the wrapper. Decryption at Runtime: The wrapper decrypts and processes the parameters, performs additional security checks, and then calls CreateFile internally. Why Use This Technique? To protect sensitive functionality from being understood or manipulated. To make reverse engineering harder by complicating the flow of API calls. To deter common hacking methods like API hooking, parameter sniffing, or call redirection. In summary, Advanced API Wrapping modifies and obfuscates how API calls are made without fundamentally changing the APIs themselves. Best Regards. sean.
  1. Load more activity
×
×
  • Create New...