XenocodeRCE Posted May 2, 2015 Posted May 2, 2015 Just a custom version of ConfuserEX 0.5 Nothing that special, very humble modifications I post it here in order to know what shall I improve https://www.sendspace.com/file/p1fsts 1
XenocodeRCE Posted May 2, 2015 Author Posted May 2, 2015 Alcatrazz successfully deobed this and give me hints about how I shall improve this ! It's time to do some research about the MSIL and clr structure ...
RDGMax Posted May 2, 2015 Posted May 2, 2015 I already made a net obfuscator But now I will make a .NET Scrambler anti decompiler, Will be called cachi chien obfuscator 2
CodeExplorer Posted May 6, 2015 Posted May 6, 2015 ConfuserExFixer does the job for metadata problems!Deobfuscated file:https://www.sendspace.com/file/il8370
XenocodeRCE Posted May 6, 2015 Author Posted May 6, 2015 (edited) ConfuserExFixer does the job for metadata problems! Deobfuscated file: https://www.sendspace.com/file/il8370 Constants still remains encrypted Edited May 6, 2015 by SpoonStudio
n0th!ng Posted May 6, 2015 Posted May 6, 2015 (edited) to fix metadata just use Universal fixer (without .NET options) next change number of streams to 9 then pass it to de4dotuse ConfuserExSwitchKiller to deobfuscate cflow obfuscation then code some tool to fix constants looking forward to see your modded ConfuserEx CrackTest2_fix-cleaned.rar Edited May 6, 2015 by n0th!ng 4
XenocodeRCE Posted May 6, 2015 Author Posted May 6, 2015 to fix metadata just use Universal fixer (without .NET options) next change number of streams to 9 then pass it to de4dot use ConfuserExSwitchKiller to deobfuscate cflow obfuscation then code some tool to fix constants looking forward to see your modded ConfuserEx Nicely done ! With Antitamper de4dot would have messed up the assembly so beware I'm constantly improving ConfuserEX, it takes me about 4h a day, reading ECMA and so on. I may post another chall at the very end of the week (Hint : clr emulation || PE32+)
Solution CodeExplorer Posted May 7, 2015 Solution Posted May 7, 2015 Here is my unpacked:https://www.sendspace.com/file/3g70nn The button code does nothing from what I've saw! 1
Sh4DoVV Posted December 23, 2016 Posted December 23, 2016 (edited) hi CodeCracker how to unpack this dll ? this file obfuscated by confuserex custom please help me thanks Edited December 23, 2016 by Teddy Rogers
SkyProud Posted December 23, 2016 Posted December 23, 2016 (edited) Check: ConfuserEx v1.0.0 The version number is v1.0.0 In CFF Explorer, open MetaData Streams - #Blob, and you will see that in the Ascii section. Edited December 23, 2016 by SkyProud Further details provided.
XenocodeRCE Posted December 23, 2016 Author Posted December 23, 2016 2 hours ago, SkyProud said: Check: ConfuserEx v1.0.0 The version number is v1.0.0 In CFF Explorer, open MetaData Streams - #Blob, and you will see that in the Ascii section. wrong its v0.5, i faked the version info. Don't rely on this kind of things, go and deep-analysis the file
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now