Jump to content
Tuts 4 You

[UnpackMe] - iChallengeYou UnpackMe #1


iChallengeYou

Recommended Posts

iChallengeYou

Hello all, Are you alone too with Christmas like me? And don't know what to do, then i will challenge you all for a new competition. I created a unpackme with selfmade code, so none protector is used, all coded by me. The goal is to find the original entrypoint, or make a running dump.


 


Goodluck and merry xmas  :rudolph: 


 


 


1. Gold: SHADOW785


2. Silver: SmilingWolf


3. Bronze: GIV


 


 


Note: The unpackme doesn't run in winXP for a unkown reason.


 


 


iChallengeYou UnpackMe #1.rar


Edited by iChallengeYou
  • Like 1
Link to comment
iChallengeYou

Very easy.

Some stolen imports ... (i'm in a quick rush) ....

 

Probably you had a very quick rush because there are no stolen imports. Also the file is not unpacked correctly, you just unpacked the first layer which is Aspack for filesize reducing :P

Link to comment

Sure.


The OEP is:



 


005F74C0



But strange... under XP SP3 your file does not run ( i have unpacked the first layer under 7 X64 and used the ESP stuff).


Was my mistake that i have not double checked if is the final OEP not the second protector OEP.


Take a look in attach. I have made a video for you.


 


Desktop.7z

Link to comment
iChallengeYou

Yes as I told in the first post for a unkown reason the packed file won't run in winxp, the unpacked does.


But thanks for spending time to my challenge :)


Link to comment
iChallengeYou

This time you got the rigth oep, congrats for that :) , but you modified (or destroyed) the import-table which is not needed, so your dump still not running here.


Link to comment
iChallengeYou

Nice job SmilingWolf!


 


Giv, the dump is finally running, so good job :)


But i still do not understand why you touch the imports, i didn't modified/protected the import-table at all.


 


I will edit the first post to rank you, and be ready for the next challenge soon ;)


Edited by iChallengeYou
Link to comment

Or i'm stupid or Win 7 does something strange to imports.


If i did not patch that address the imports are going crazy to other locations as it should be.


Noticed that to a PEP 5 unpackme also.


XP is way better to unpack than 7.


Link to comment

Nice job SmilingWolf!

Giv, the dump is finally running, so good job :)

But i still do not understand why you touch the imports, i didn't modified/protected the import-table at all.

I will edit the first post to rank you, and be ready for the next challenge soon ;)

Next time do a unpackme that runs on XP.
Link to comment
iChallengeYou

Next time do a unpackme that runs on XP.

 

Don't blame me, i can't help that you can't handle =>win7 :)

 

But for the next challenge i hope the xp issue is solved for then.

Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...