Challenge of Reverse Engineering
Try a challenge or contribute your own, any platform or operating system...
The creation of new topics is disabled in these subforum categories.
Please create and post your new challenges in the appropriate subcategory of Downloads > Challenge of Reverse Engineering
A topic will then automagically be created and posted in these forums...
-
Example CrackMe - Debug Blocker x64
by Teddy Rogers- 3 replies
- 11.8k views
View File Example CrackMe - Debug Blocker x64 This is an example for submitting a CrackMe in the Downloads section of the site. You can download the file and run Debug Blocker x64. Nothing too exciting will happen! The challenge here would be to patch the debug-blocker function so that it does not spawn a second process. Submitter Teddy Rogers Submitted 02/23/2020 Category CrackMe
-
Enigma Protector 5.2 1 2 3 4
by GIV- 93 replies
- 98.2k views
Difficulty : 3 Language : Delphi Platform : Windows X86 OS Version : XP and above Packer / Protector : Enigma Protector 5.2 Description : Small unpackme for you guys to try. Screenshot : Enigma Protector 5.2 unpackme.rar
-
[DevirtualizeMe] VMProtect 3.0.9 1 2
by HellSpider- 42 replies
- 73k views
Difficulty : 8 Language : C++ Platform : Windows 32-bit and 64-bit OS Version : All Packer / Protector : VMProtect 3.0.9 Description : The objective is to interpret virtualized functions in the attached binaries. No additional options have been used - no memory protection, no import protection and no compression. The virtualized function(s) will execute when the following key(s) is/are pressed: VMP32 (V1) : P VMP32 (V2) : 1 and 2 VMP64 (V1) : P VMP64 (V2) : 1 and 2 The virtualized functions are not very large. Detailed information of the interpreting procedure/internals or a complete solution paper is pref…
-
[CrackMe].Net Reactor Modded 1 2
by MindSystem- 46 replies
- 72.5k views
Hello, i found a special crackme obfuscated with .net reactor 4.9. I think his version of .net reactor is modded Here's the file : http://www5.zippyshare.com/v/2225980/file.html I'm working with the file since 5 days and i didn't find any solution. If someone can help me Cra'ckMe.zip
-
Python Pyarmor + My Protector 1 2
by 0x72- 45 replies
- 65.3k views
Language : Python Platform : Windows OS Version : All Packer / Protector : Pyarmor + My Protector Description : Want to see if someone can unpack it, want to use this obfuscator for my future aplications in python Screenshot : Spoiler Download : Virustotal: https://www.virustotal.com/gui/file/fec987a11c8bdd47355529389d75f1f2cb0f980a763efa21e796dd1a21619989/detection Download: https://anonfile.com/3fn5o8gdo5/UnpackME_by_0x72_rar UnpackME by 0x72.rar
-
[UnpackMe] Themida 2.2.6.0 1 2
by nProtect- 42 replies
- 58.8k views
Hi all, This file is compiled with Visual Studio 2010 (C++ Language) and protect one with VM_START/VM_END. New themida version have new VM system so I have use FISH32 White VM to protect this file ThemidaTest.rar
-
[unpackme] VMProtect 2.06 unpackme 1 2 3
by EvOlUtIoN- 66 replies
- 57.3k views
Here it is an unpackme wioth maximum VMProtect protection. It have also a boxed dll which should be a good and never seen target to unpack. Good luck. VMProtector_2.06_unpackme.rar
-
[unpackme] Safengine Shielden 2.1.9.0 1 2
by Xjun- 42 replies
- 51.3k views
Unapck Safengine! unpackme.rar
-
Unpack Challenge (Agile.NET) 1 2
by Fr4x- 43 replies
- 51.2k views
Language : C# .Net Platform : Windows x32/x64 OS Version : All Packer / Protector : Agile.Net v6.6 Description : Hi everyone, hope one of you friends can unpack the target and teach us how to unpack it Screenshot : Secured.rar
-
[DevirtualizeMe] VMProtect 2.13.5 1 2
by HellSpider- 39 replies
- 50.8k views
Hi. I created an unpackme using VMProtect 2.13.5. The only task is to devirtualize the blocks of code that are virtualized. There are 7 short functions. Each will execute when keyboard numbers 1-7 are pressed. The functions are virtualized as follows: 1 - Only mutation with no additional options 2 - Virtualization with no additional options 3 - Virtualization with the VM integrity check option 4 - Virtualization with the register scrambling on VM exit option 5 - Virtualization with the hide constants option 6 - Virtualization with all 3 extra options 7 - Ultra mode (which means mutation + virtualization) with all 3 extra options The pu…
-
[Unpack]Crypto+Confuser 1.9
by patchaya- 14 replies
- 49.5k views
How to Clean & String Decrypt , Thank you UnpackMe.rar
-
VMProtect v3.5.0.1213 1 2
by whoknows- 29 replies
- 48.3k views
View File VMProtect v3.5.0.1213 Try to unpack or alternatively provide a serial. If there is no solution provided by Saturday 11am (GMT+0) I will attach the same without debugger detection. Protections used: Debugger detection (User-mode + Kernel-mode) Ultra (Mutation + Virtualization) Submitter whoknows Submitted 08/06/2020 Category UnPackMe (.NET)
-
- 25 replies
- 47.8k views
Unpackme : VMProtect Ultimate v3.0.1.465 Protection option .: Complete Protection Linker : Delphi Download: http://release.crack4r.cc/Exercise/VMProtect_Ultimate_v3.0.1.465.UnpackMe.7z have fun, Best regards, Sound
-
[InlineMe] VMProtect IsValidImageCRC() 1 2 3
by SunBeam- 51 replies
- 47.4k views
[ Solutions so far: JohnWho, What ] (read whole thread) Hello folks. Decided I would post this here as well, as we're lacking some exercise on these kinds of targets. Purpose: open up the test target, click OK on the message box. Use any tool you want to alter a byte in application's active memory (e.g.: "MZ" string at ImageBase) and another message will appear. Goal: make the 'bad' message never pop-up, but not through patching the all-too-clear JUMP. Inline VMProtect's CRC check method so the CALL always returns 1. Again, not through MOV EAX,1|RETN (P.S.: imagine you don't know where this function is in a well-obfuscated target). …
-
[unpackme]WinLIcense 2.0.8.0 + Hardaware lock 1 2 3 4
by EvOlUtIoN- 80 replies
- 45.3k views
Here is a new unpackme protected with latest version of WinLicense (2.0.8.0). I put maximum protection, and locked it to hardware, so it requires a keyfile to run (provided of course). Goal is to unpack it, or also bypass of hardware lock (make program run on all machines) can be a good solution. Good luck. EvOlUtIoN wl2080_unpackme.rar
-
The Enigma Protector v6.9 1 2 3
by GIV- 59 replies
- 43.7k views
View File The Enigma Protector v6.9 I have protected a simple file with the Enigma Protector 6.9. Try to unpack. For a skilled reverser will not be as hard as it seems. HWID: A7707-65A71-43529-A59E1-41C2F-C5AA0-EB308-3F774 Name: tuts4you Key: BG8QC4UMZW3QMTH99U6ZTF8FJJNDAPKY5E2XNL3CMHRVUMLSB2QWRBSYBGF4RNHX7WC26W2GQMNBNPUU3YUTDXDS387A2UURMUVJ88P5PPC9ZCEQHFHW4J6ZQRAK7GW6DRK4QH4CGCEQM7F9K39J89S4CRARX3L3LPABBXU23M8QXP6A85L2CZFJZF66KF5NFTZ557872DA3 Submitter GIV Submitted 07/20/2021 Category …
-
[unpackme]Themida 2.0.3.0 - UnpackME 1 2 3
by Sp1d3rZ- 65 replies
- 43k views
Themida v2.0.3.0 - UnpackMe Protection Level = V.HARD I give u Protection Details for making ur unpack easy ==Protection Options== Anti-Debugger Detection = Ultra Advanced API-Wrapping = Level2 Anti Dumpers = Enable Anti- Patching = File Patch (Sign Support) Entry Point Obfuscation = Enable Metamorph Security = Enable Resource Encryption = Enable Memory Guard = Enable VMWare/Virtual PC = Compatible Compression = App/Res/Secure Monitor Blockers = File Monitors/Registry Monitors Delphi/BCB Form = Enable When Debugger Found = Exit Silently Code Replace = Enable ==Advanced Option== Encrypt App = Enable .NET ASM = Enable Hide from PE = Type2 When U DID I…
-
Little Hard Enigma 5.6 1 2
by Apuromafo- 33 replies
- 41.7k views
testing about 3 trial sdk Difficulty : 4 Language : Delphi 7 SE Platform : Windows X86 OS Version : XP and above Packer / Protector : Enigma Protector 5.6 Description : Little hard unpackme for do a tutorial/tut maybe is hard because i not gived info of registration BR, Apuromafo SS: i know there with all harcoded things not must be imposible atached ide.dll only for unpacked if really need link Desktop.7z
-
Enigma Protector 5.1 1 2
by GIV- 29 replies
- 41.2k views
Difficulty : 3 Language : Borland Platform : Windows X86 OS Version : XP and higher Packer / Protector : Enigma Protector 5.1 Description : Small unpackme. Is in fact a crackme that i have fund on the www and apply a Enigma protector layer. So the goal is to unpack. IMHO is not hard at all. So i give you a valid combo of HWID/name/key: HWID: 58603-7C96E-050B3-811FC NAME: giv@reversing.ro Key: KWFM62F-NMH8E94-BH2C98E-FDDEQHG-VK88BVD-PRXLNZA-FM6TWL7-U6NNJGL-3K5CMQY-BSXJM8W-LZ2NYTL-QWXQ69F-XBDPTNY-GWSNX2M-YTKJV9E-YHRWUPQ The file have a password too witch is very easy to bypass. Good luck! Screenshot : Crack Auth_Protected…
-
Difficulty : 10 Language : C# Platform : Windows OS Version : Winall Packer / Protector : DNGuard v3.80 - HVM not applied (will expire 26/12) Description : Provide serial or unpack me ggggg.rar
-
Beds Protector 4.5 1 2
by Guest Steve- 28 replies
- 39.6k views
Difficulty : medium Language : c# Platform : Windows x32/x64 OS Version : All Packer / Protector : BEDS 4,5 Description : unpack and tell how fast did you unack it and the way if possible Screenshot : ConsoleApp1.rar
-
.NET Reactor v6.3 1 2
by whoknows- 26 replies
- 39.1k views
View File .NET Reactor v6.3 Try to unpack or alternatively provide a serial. Protections used: Necrobit Antitampering Antidebug Obfuscation Code Virtualization + Shield with SNK Submitter whoknows Submitted 06/10/2020 Category UnPackMe (.NET)
-
View File WinLicense v3.1.3.0 x86 (All Protection Options) UnpackMe - WinLicense 3.1.3.0 x86 Full Protect HWID Lock + Entry Point Virtualization + Etc... HWID: 1111-2222-3333-4444-5555-6666-7777-8888 Author:boot From:Tuts4you Time:2023.04.02 Submitter boot Submitted 04/02/2023 Category UnPackMe
-
[UnPackMe] Safengine Shielden 2.2.6.0 1 2
by _or_75- 25 replies
- 38.3k views
Project1_se.rar
-
Easy Unpackme Enigma 5.6
by Apuromafo- 18 replies
- 36.6k views
Difficulty : 0 Language : free pascal /Lazarus IDE x86 Platform : Windows X86 OS Version : XP and above Packer / Protector : Enigma Protector 5.6 Description : Small unpackme for do a simple tutorial maybe is easy, but i hope there you too can do tutorial BR, APuromafo Silver= unpacked.exe Bronce=unpacked +tutorial Gold=unpacked+tutorial+script PID scan: Scanning -> C:\project1_protected.exe File Type : 32-Bit Exe (Subsystem : Win GUI / 2), Size : 6942172 (069EDDCh) Byte(s) | Machine: 0x14C (I386) Compilation TimeStamp : 0x00000000 -> Thu 01st Jan 1970 00:00:00 (GMT) -> File has 933852 (0E3FDCh) bytes…