Cursedzx Posted October 6, 2018 Share Posted October 6, 2018 Difficulty : Probably 7 Language : C# .NET Platform : Windows (anyCPU) OS Version : Windows 7 Above Packer / Protector : Atipls' obfuscator Description : Upload the unpacked file and give me a detailed tutorial. Describe me the specific method or the specific tools in order used. As I said in the previous unpack challenges XD. Screenshot : UnpackME.exe Link to comment Share on other sites More sharing options...
Solution #Sith Posted October 7, 2018 Solution Share Posted October 7, 2018 Load file in dnSpy, bypass NtQueryInformationProcess, dump the module, then de4dot and SAE (string only). UnpackME_unpk.exe 1 Link to comment Share on other sites More sharing options...
Cursedzx Posted October 7, 2018 Author Share Posted October 7, 2018 Sith, do you know what NtQueryInformationProcess was used for? Link to comment Share on other sites More sharing options...
evlncrn8 Posted October 7, 2018 Share Posted October 7, 2018 probably anti debug.. Link to comment Share on other sites More sharing options...
collins Posted October 7, 2018 Share Posted October 7, 2018 3 hours ago, #Sith said: Load file in dnSpy, bypass NtQueryInformationProcess, dump the module, then de4dot and SAE (string only). UnpackME_unpk.exe @Sith how to bypass NtQueryInformationProcess ? Can you a little more detail ? Link to comment Share on other sites More sharing options...
#Sith Posted October 7, 2018 Share Posted October 7, 2018 4 hours ago, Cursedzx said: Sith, do you know what NtQueryInformationProcess was used for? InheritedFromUniqueProcessId field in PROCESS_BASIC_INFORMATION structure get the ID of the parent process and programm compare it to the some names. I Just changed the InheritedFromUniqueProcessId value to the ID of explorer.exe Link to comment Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now