Leaderboard
-
m!x0r
Full Member32Points42Posts -
jackyjask
Full Member+17Points1,634Posts -
Teerayoot
Junior+8Points22Posts -
4n0nym0us
Junior8Points5Posts
Popular Content
Showing content with the highest reputation since 07/20/2009 in File Comments
-
AT4RE Power Loader
6 pointsThe tool created with love for all RCE community. If you have any feedback bug repport share it here...6 points
-
4n4lDetector
5 points4n4lDetector 3.0.0 Download: https://github.com/4n0nym0us/4n4lDetector/releases/tag/v3.0 [+] The function search code for "Import Table" and "Call Api By Name" has been optimized. [+] A general optimization has been performed with one of the largest buffers in memory, this positively affects the stability and speed of the general analysis. [+] The size of the file to be analyzed has been increased by default to 50MB. [+] An optimization has been made in the search engine for the "Show Offsets" option and in the handling of buffers. [+] Searches for generic malware terms, different types of exploitation, APTs and terminologies that may affect the State in "4n4l.Rules" have been included. [+] A cleaning of null bytes 0x00 is performed in the variable where the report is stored to avoid bugs in the output of the text box of the main form. [+] The tool interface takes on a darker base tone. [+] A donation button via (PAYPAL) has been included since I have finally decided to continue with the project publicly for everyone. [+] A bug was fixed in which false functions could be included in the "Export Table" list by carving. [+] The Interest's Words module includes new internal words for the tool, for ansi and unicode. [+] A bug in the web view was fixed that could aesthetically affect the view of the Interest's Words module statement. [+] Optimizations were made in the Known IP/Domains module for ansi and unicode. [+] New search syntaxes were included in the "Intelligent Strings" module to increase interesting results. -> Internal cleanup syntaxes were added to show more stylized results. -> An optimization has been made with a direct impact on the variables used in this module. [+] A more selective cleaning of the extracted URLs is performed: -> URLs with extensions in the context of PKI digital certificates are reconstructed. -> Htm extensions are reconstructed. -> ".com" domain endings are cleaned. -> Possible HTML code cleaning is performed. [+] A progression system based on medals has been included. -> Brown Padawan Medal, Bronze Medal, Silver Medal, Gold Medal and Platinum Medal. -> The process can be slow, don't despair... because it's worth it. -> These medals will be earned as you use the tool over the course of days, weeks, months and consequently their functionality will also increase progressively. -> The medals will only work on the work machine on which they have been earned, if you want to make it work on another machine of yours try it yourself (You're a hacker, right?). -> The features or surprises that come with leveling up are not included in this file, although you can review them in the "Settings" section of the tool.5 points
-
AT4RE Power Loader
4 points
-
AT4RE Power Loader
4 points
-
AT4RE Power Loader
4 pointsThe best loader at all. For packed exe and dll. Moreover it is antivirus friendly !!!! The created loader is not detected by windows defender as a malware or a virus. Thanks to at4re And thanks to our forum members for the sharing4 points
-
Joker Italy Manual Unpacking Tutorials
This thing helped me to play Joker's exe (packaged swf) https://github.com/Aira-Sakuranomiya/CleanFlashInstaller/releases4 points
-
ARTeam Tutorials
4 points
-
AT4RE Power Loader
3 points
-
AT4RE Power Loader
3 pointsNew Version 0.9 Published Release Date: 06/09/2025 [+] New Checkbox in Options Form - Creat a Loader For Windows XP. Loader Details: [+] Loader Now Full Support Windows XP x32 and x64.3 points
-
AT4RE Power Loader
3 points
-
AT4RE Power Loader
3 pointsTested Successfully with Targets Protected by: VMProtect، Themida, EXECryptor, Obsidium, The Enigma Protector....3 points
-
Joker Italy Manual Unpacking Tutorials
Yes, you need to install trillix swf decompiler. https://cdn.eltima.com/download/flash_decompiler.exe Regards. sean.3 points
-
Exeinfo PE
3 pointsVersion : 0.0.8.3 - ( 1183 / 169 - x64 signatures ) www Last site update : 2024-02-24 https://github.com/ExeinfoASL/ASL/releases/tag/exeinfo Added pack .lzma , .lzma Undetectable , .lzma unpacker config : added [Internet Browset ] change to user path Viewer : added [ Save to File - window log ] fixed VMprotect v3.5+ added : Inno unpacker script view Exe Rippers - save to created Directory : !Rip_exe_{file_name} added overlay detector l + section ovl scan [ Python .Zlib Archive "PYZ" added Function : Detect_BoxedApp_SDK32 Ripper .7z xor FF - fixed , detect crypted 7z v.0.4 in Advanced Installer [ v19.x ] Set Buffer for exe file : 336 MB Lzma packer ( now you can send malware file via gmail ) : exeinfope.exe FileName /plzma - pack file with lzma packer ( 7z compatible ) for many files ( mask files ) : console mode - exeinfope.exe FileName* /plzma - pack file with lzma packer Lzma unpacker : exeinfope.exe FileName /ulzma - unpack file with lzma packer ( 7z compatible ) for many files ( mask files ) : console mode - exeinfope.exe FileName* /ulzma - unpack file with lzma packer update Obsidium v1.5 - 1.8.2.2 added detector for DLL 32bit : [ plugin for : AutoPlay Media Studio ] v8.5 http://www.indigorose.com added detector for DLL 64bit : [ .PYD Python C Extensions library ] added console mode : unpack all exe files and Inno script from InnoSetup installer ( work only if you don't have installed Inno Extractor - Exeinfo Pe internal unpacker ) parameter example : exeinfope.exe file_name /unp-inno-exe added Skater v24.2.0.51 2024 ( protected DLL still not detected ) Delphi version resolver Added ( not 100% ) : Delphi XE7 - v10.4 , Delphi v10.4 Sydney , Delphi v10.4 Rio , Delphi v11.0 Alexandria , Delphi v12 Yukon , Delphi v10.2 Tokyo , Delphi v10.1 Berlin added Config GUI : Wow64 redirect added [Internet Browset ] change to user path added Inno extractor - view inno script added to NOT EXE - .7z 7-ZIP Archive v.0.4 [ AES - detected - password required ] [ Mode : DEFLATE ] [ Mode : P7Z_BCJ ] [ Mode : LZMA:21 BCJ ] added detector for protected 7zip : Ripper don't ripp "protected .7z archives by CryptoNickSof" but Exeinfo PE detect it ! and others ...3 points
-
Tuts 4 You UnpackMe Collection (2016)
Download works fine. MD5 checksum should look like this... Tuts_4_You_UnpackMe_Collection_(2016).rar : ebbc1fe726986f9d8f1e1ca1c3a08c67 Ted.3 points
-
AT4RE Power Loader
2 pointsThank you for sharing. These tools are beneficial for the development of AI in the future. AI GENERATOR PATCH HOOK .DLL can simply write commands and automatically specify patch points through AI decryption calculations. I just write commands and AI can patch points in whatever I want everything. In the world of the future, human thoughts will be embedded within AI intelligence. It will be extremely smart, with everything gathered from the ideas of people around the globe. Our work will become easier and it will continue to evolve for the benefit of all humankind.2 points
-
AT4RE Power Loader
2 points2 points
-
AT4RE Power Loader
2 pointsUse DLL tracer then try 5 last dll name in wait lib feature or increase loader timer delay between 2000000-50000002 points
-
Exeinfo PE
2 points
-
AT4RE Power Loader
2 points
-
AT4RE Power Loader
2 points
-
HexRaysCodeXplorer (Recompiled for IDA Pro)
YES! 9.1 GA (find it here as a torr) 90beta is buggy2 points
-
Exeinfo PE
2 points
-
ARTeam Tutorials
2 pointsNew download link: https://workupload.com/file/msCSm45zjQm Download link working fine, in my test.2 points
-
Remote process injection.
2 pointsrelease 1.42 +support x86 injection(LdrLoadDll) +fix bug(load patch file) Remote Process Injector1.42.rar2 points
-
Exeinfo PE
2 points
-
4n4lDetector
2 points
-
4n4lDetector
2 points4n4lDetector 2.9.0 Download: https://github.com/4n0nym0us/4n4lDetector/releases/tag/v2.9 [+] New logo of the application by Sandra Badia Gimeno (www.sandrabadia.com). [+] Relocated Kernel-mode functions to the Suspicious Functions section. [+] Surprises are included so you don't get bored with daily use of the tool. [+] A multitude of tests were carried out focused on providing the greatest stability, speed and effectiveness of the extracted contents. [+] Optimization during idle state. File creation checks are no longer performed for the PECarve and UPX functionalities. [+] Detection of sections that allow writing from flags was included. [+] The extraction of functions from the "Export Table" using Carving has been slightly improved. [+] The name of the file under analysis has been included in the content of the report. [+] Added a longer description about the possibilities of the Zombie_AddRef function. [+] Fixed a bug where the "Show Offsets" tool dump did not allow reading a small portion of the end of the analyzed file. [+] Now when you click on the Virustotal result in the main form, it will take us to the analysis web page. [+] Virustotal analysis has been included in the analyzes carried out from console mode. [+] Review of Shikata_ga_nai detections and update of Payload detection heuristics. [+] Increased and improved the query extraction functionality of the ASCII and UNICODE records branch. [+] Increased and improved the ASCII and UNICODE SQL query extraction functionality. [+] Increased and improved URL extraction functionality, also searches FTP and SFTP in ASCII and UNICODE. [+] Increased and improved ASCII and UNICODE file name extraction functionality. -> .EXE, .DLL, .BAT, .VBS, .VBE, .JSE, .WSF, .WSH, .PS1, .PSM1, .PSC1, .SCR, .HTA, .DLL, .PIF, .MSI , .MSP, .SYS, .CPL, .JAR, .TXT, .INI, .PDF, .WDS, .DOC [+] The word finder has been completely delimited for any search location of the text boxes. -> In web view the browser is now automatically blocked. [+] Fixed a rare error in the IPs section that could lead the execution thread to a loop without finishing analyzing the files. -> This fix also fixed the ability to end analysis with a single active option in the tool's modules panel. [+] The 4n4l.rules module now internally converts text format rules "T:" to Unicode format. -> The rules of this file have been optimized, now search more with less. [+] The bytes to be reviewed at the Entry Point by the rules file are increased from 100 to 1500. -> Revised some of the rules to eliminate false positives after the update. [+] The reading of the rule files is done only once after starting the application or after the first analysis, then it is loaded into memory for future uses. -> The charging status can be checked from the "Settings" section. [+] Added the tilde (~), the dollar ($), the single quote (') and the double quote (") as characters that can be part of the reports. -> A conversion filter is applied to these quotes for the tool's Web view. [+] Worked on the efficiency of the "Intelligent Strings" module. -> The length of strings to be analyzed was increased in all the Strings functionalities of the tool (75% longer strings). -> Specific cleanup of anomalous characters is now performed and new ones are allowed. -> Search words were extended. [+] Added a graph in charge of displaying the content of the executables and any analyzed files. -> The executable header is displayed in blue. -> The identified sections are divided between magenta for the executable sections and black for the rest. -> The excess code of the executables will have a red color as in Crypters, Binders, Joiners... -> If the analyzed section contains an RSize of zero, its content will not be painted on the graph. -> If the file is not a Windows executable, it will be scanned for printable characters and the absence of printable characters. Blue and black when there is no content. -> When you double click on the graph, it will automatically be saved in the analysis folder. -> The executions measure the console mode of the application "-TXT", "-HTML" or "-GREMOVE" include the graph as analysis output.2 points
-
4n4lDetector
2 points
-
Joker Italy Manual Unpacking Tutorials
yeah, smth is not good maybe it works only on Win XP? its 20 years old... this is all I see - does not start to play2 points
-
Baymax Patch toOls
2 points
-
Coding Loaders in C++
2 points
-
Baymax Patch toOls
2 points
-
Sentinel SuperPro (Removing Dongle Protection)
2 points
-
Lena's Reversing for Newbies
2 pointsThere is adobe debug flash player that will help you play lena151 videos h****://www.adobe.com/support/flashplayer/debug_downloads.html2 points
-
Lena's Reversing for Newbies
2 pointsSince flash is killed and lena151 tuts are in flash here is quick help to open the files https://drive.google.com/drive/folders/1lmqCzf2vNoddp70wrWBKS_GS7iPLD-RN?usp=sharing2 points
-
Address Shortcuts
2 points2 points
-
OllyICE
2 points
-
OllyPath2
2 pointsBy seeing the number of imports on your screenshot and the ollydbg.exe in upper case i would guess you tried this on ollydbg v1.10, not on ollyv2 The description don't mention it here but that thing is for v2, if you look inside the readme of the archive, it says (in french) that the code has been rewrote for olly 2. So try with v2, or recompile the dll for v1. Also i'm checking the src and this can really be improved more. Especially for the v2 as if you rename ollydbg.exe to blabla.exe, then it will look for blabla.ini, but OllyPath2 will create only 'ollydbg.ini' as this string is in hard inside.2 points
-
Lena's Reversing for Newbies
1 pointI registered just to say thank you for this. Also, I plan to contribute as much as I can. If not, then I can at least give likes where they are deserved :)1 point
-
Tuts 4 You UnpackMe Collection (2016)
1 point
-
NuMega SmartCheck
1 point
-
Lena's Reversing for Newbies
1 point
-
OllyICE
1 point
-
Lena's Reversing for Newbies
1 point
-
diablo2oo2's Ollydbg
1 point
-
Fravias First Period: Reverse Engineering ("Reality Cracking") (1995 - 1999)
This was the time I was active, did dongles and stuff, compare with now, that was easy, I did now the rocky4 and set on all the switches of the program flow. it is quite fun, attacking the dongle does not work well, emulating is fun. I had the first computer in 1989 a dos, 20 Mb harddisk, yes these costs mony that time, and much more the cd C:\ was not possible, are real tekst machine, not more. Hardisk was in that time 2160 gulden, for 20Mb.1 point
-
Fonts i am most use
1 point
-
cct15k
1 pointHidden part, for fun: Run the intro, open a memory editor like Cheat Engine, and set '42A674' to 2. (4 byte value)1 point
-
team PACE FileMenu-Tool NFO TRO
1 pointThe osdm version. found by accident..thinking it said Napalm... PACE_Napalium.exe1 point
-
OllyDBG - AIO
1 pointv1.1 Plugin menu not appear. after applied folder seting from also not working after restart. it resets the path OllyDBG.ini.1 point