Jump to content
Tuts 4 You

[Unpackme] WinLicense v2.2 x64


Recommended Posts

Posted

Are you tough enough to break this?


 


WinLicense with lowest possible protection options.


 


Standard Virtual Machine: TIGER64 (Red)


UnpackmeWLx64.rar

Posted

ok nice, thanks. Maybe I disabled too much options.


 


Here is another unpackme with all standard settings. TIGER64 (Red)


WLUnpackmeStandard.rar

Posted (edited)

Restoring the imports was possible, because there were only two (and I unpacked the other file). I couldn't do it when there were more virtualized imports...

Bypassing the debug detections was easy :) I just used TitanHide (+ 'dbh' command, which does basic PEB hiding).

Greetings,

Mr. eXoDia

EDIT: attached file

WLUnpackmeStandard_dump_new_size_SCY.rar

Edited by Mr. eXoDia
  • Like 2
Posted (edited)

Very nice! I didn't expect that.


 


And here is some max protection sample. Ultra anti-debug, will your TitanHide work? :showoff:


 


TIGER64 (Black)


WLUnpackmeMax.rar

Edited by Aguila
Posted (edited)

Hi Aguila :


thanks for unpack test file ,but I think it is not a big deal :sorry:   For the first unpack me.


2 steps to unpack it just :sweat:


here a tut on how to unpack by IDA 6.1


https://drive.google.com/file/d/0B402C-bcZm3lNG01Q29VMXpWSzA/edit?usp=sharing


 


For me I solve the first one ,other file which need to work with hide debugger on x64 , I think I need more practice :smartass: .


 


I think Mr. eXoDia is rocker in x64 now :yes:


Edited by ahmadmansoor
  • Like 4
  • Thanks 1
Posted

Thanks for the tutorial ahmadmansoor.


 


Most people will not be able to do this, because they don't have OllyDbg and Olly Script ;-)


Posted

Hey,

I'll also make a small tutorial for the stronger protections (especially restoring the imports)

Greetings

  • Like 7
  • 3 weeks later...
Posted

Sorry, I can not check this tutorial.
What plugin for IDA should be used?

image.png

Posted

@ChVL:try TitanHide (see my signature), then do a simple PEB patch and you're good. You can also try IDAStealth


 


Greetings


Posted

Mr. eXoDia,

Thank you very much! I will try...

I looked IDASealth, but it only for x32.

  • 10 months later...
Posted

If I keep resurrecting old threads perhaps I'll become a necromancer even better than Sauron :P


WLx64 2.2 MUPed.7z

  • Like 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...