Xons5454 Posted June 24, 2014 Posted June 24, 2014 (edited) Agressive settings on confuserex. Unpackme if you can Virustotal: https://www.virustotal.com/es/file/c8951bcfcaf7a4d137dd973f7049c5615ddf8196992ca6d02ac94299a3e1519f/analysis/1403641460/ Download: https://mega.co.nz/#!3dgWFQxB!fJzxNYoJohDGyZMRZf0IOxf1yljKvAiOaKmmQB3RXPU Edited June 24, 2014 by Byralph
Smoke Posted June 25, 2014 Posted June 25, 2014 solution: https://forum.tuts4you.com/topic/35897-confuserex-v012-unpacker/deobfuscated: mediafire.com/download/4pgjs4apx8sdkdt/Test_Exe.rar
XenocodeRCE Posted June 25, 2014 Posted June 25, 2014 You don't need to user confuserEX unpacking tools to get it deobed / unpacked 1
Hadits follower Posted June 26, 2014 Posted June 26, 2014 (edited) Post #6 i know everything how to do it but i dont know anything how i can do it . @Byralph i think refproxy replace time got exception just follow solution: https://forum.tuts4you.com/topic/35897-confuserex-v012-unpacker/ #6 Post cleaned file renamed res edited rebuild ilasm WindowsFormsApplication16_Unpacked2_ilasm.zip Edited June 26, 2014 by Death 1
Hadits follower Posted June 26, 2014 Posted June 26, 2014 (edited) this is no hf that you are posting a screenshot a easy thing what you did . here is tutorial what he did a new b also can do it. 1. download http://www.ntcore.com/exsuite.php 1. load file as cff explorer 3. go cff explorer direction "Address Converter" 4. Rva put => 0x523a 0ffset => 3431 c# noncracked "==" ___ Cracked "!=" 5. hex byte you see 2d => iL => brtrue.s edit hex 2c br => iL => brfalse.s done cracked thats it his screenshot . Try always post the exe not screenshot in this forums Test_Exe _Cracked_hisfile.zip Edited June 26, 2014 by Death 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now