Jump to content
Tuts 4 You

[Deobme] ConfuserEX 0.5 custom


XenocodeRCE
Go to solution Solved by CodeExplorer,

Recommended Posts

XenocodeRCE

Alcatrazz successfully deobed this and give me hints about how I shall improve this !


 


It's time to do some research about the MSIL and clr structure ...


Link to comment
I already made a net obfuscator

 

But now I will make a .NET Scrambler anti decompiler, Will be called cachi chien obfuscator

  • Like 2
Link to comment

to fix metadata just use Universal fixer (without .NET options) next change number of streams to 9 


then pass it to de4dot


use ConfuserExSwitchKiller to deobfuscate cflow obfuscation 


then code some tool to fix constants 


 


 


looking forward to see your modded ConfuserEx 


CrackTest2_fix-cleaned.rar

Edited by n0th!ng
  • Like 4
Link to comment
XenocodeRCE

to fix metadata just use Universal fixer (without .NET options) next change number of streams to 9 

then pass it to de4dot

use ConfuserExSwitchKiller to deobfuscate cflow obfuscation 

then code some tool to fix constants 

 

 

looking forward to see your modded ConfuserEx 

 

Nicely done ! With Antitamper de4dot would have messed up the assembly so beware

 

I'm constantly improving ConfuserEX, it takes me about 4h a day, reading ECMA and so on.

 

I may post another chall at the very end of the week (Hint : clr emulation || PE32+)

Link to comment
  • 1 year later...

hi CodeCracker

how to unpack this dll ?

this file obfuscated by confuserex custom

please help me

thanks

 

Edited by Teddy Rogers
Link to comment

Check: ConfuserEx v1.0.0

The version number is v1.0.0

In CFF Explorer, open MetaData Streams - #Blob, and you will see that in the Ascii section.

 

CFF_Explorer1.PNG

Edited by SkyProud
Further details provided.
Link to comment
2 hours ago, SkyProud said:

Check: ConfuserEx v1.0.0

The version number is v1.0.0

In CFF Explorer, open MetaData Streams - #Blob, and you will see that in the Ascii section.

 

CFF_Explorer1.PNG

 

wrong its v0.5, i faked the version info. Don't rely on this kind of things, go and deep-analysis the file

Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...