Posted February 3, 201411 yr Are you tough enough to break this? WinLicense with lowest possible protection options. Standard Virtual Machine: TIGER64 (Red)UnpackmeWLx64.rar
February 4, 201411 yr Doesn't seem like a tough challenge, but I didn't do anything with a VM... GreetingsUnpackmeWLx64_dump_size_SCY.rar
February 4, 201411 yr Author ok nice, thanks. Maybe I disabled too much options. Here is another unpackme with all standard settings. TIGER64 (Red)WLUnpackmeStandard.rar
February 4, 201411 yr Restoring the imports was possible, because there were only two (and I unpacked the other file). I couldn't do it when there were more virtualized imports... Bypassing the debug detections was easy I just used TitanHide (+ 'dbh' command, which does basic PEB hiding). Greetings, Mr. eXoDia EDIT: attached file WLUnpackmeStandard_dump_new_size_SCY.rar Edited February 4, 201411 yr by Mr. eXoDia
February 4, 201411 yr Author Very nice! I didn't expect that. And here is some max protection sample. Ultra anti-debug, will your TitanHide work? TIGER64 (Black) WLUnpackmeMax.rar Edited February 4, 201411 yr by Aguila
February 5, 201411 yr Hi Aguila : thanks for unpack test file ,but I think it is not a big deal For the first unpack me. 2 steps to unpack it just here a tut on how to unpack by IDA 6.1 https://drive.google.com/file/d/0B402C-bcZm3lNG01Q29VMXpWSzA/edit?usp=sharing For me I solve the first one ,other file which need to work with hide debugger on x64 , I think I need more practice . I think Mr. eXoDia is rocker in x64 now Edited February 5, 201411 yr by ahmadmansoor
February 5, 201411 yr here is attached UnpackmeWLx64ByIda.rar Ps: this is ahmadmansoor unpacking tut Edited February 5, 201411 yr by Dreamer
February 5, 201411 yr Author Thanks for the tutorial ahmadmansoor. Most people will not be able to do this, because they don't have OllyDbg and Olly Script ;-)
February 5, 201411 yr Hey,I'll also make a small tutorial for the stronger protections (especially restoring the imports)Greetings
February 24, 201411 yr @ChVL:try TitanHide (see my signature), then do a simple PEB patch and you're good. You can also try IDAStealth Greetings
February 24, 201411 yr Mr. eXoDia, Thank you very much! I will try... I looked IDASealth, but it only for x32.
January 23, 201510 yr If I keep resurrecting old threads perhaps I'll become a necromancer even better than Sauron WLx64 2.2 MUPed.7z
Create an account or sign in to comment