Jump to content
Tuts 4 You
  • 0
Sign in to follow this  
zodiac

ILProtector + Enigma - (Unpack & Get the Password)

Question

zodiac

Language : . NET
Platform : Windows
OS Version : Windows 7/Windows 8/Windows 10
Packer / Protector : ILProtector + Enigma

Description :

Unpack the file and get the password.

Screenshot : 

Capture.JPG.6a1a816aad03ee7037107021258372a6.JPG

Test_protected.rar

Share this post


Link to post

12 answers to this question

Recommended Posts

  • 0
3dsboy08

File does not seem to be runnable on my VM - please fix this before I can continue.

Share this post


Link to post
  • 0
CodeExplorer

After you dump the main exe (.NET) with MegaDumper:

Exception messages:
   Unable to load DLL 'Test32.dll': The specified module could not be found. (Exception from HRESULT: 0x8007007E)

So you got to dump that dll with DllSaver.

Enigma Only unpacked exes:
https://www95.zippyshare.com/v/b0258Ft4/file.html

 

  • Like 1

Share this post


Link to post
  • 0
cawk
6 hours ago, CodeExplorer said:

After you dump the main exe (.NET) with MegaDumper:

Exception messages:
   Unable to load DLL 'Test32.dll': The specified module could not be found. (Exception from HRESULT: 0x8007007E)

So you got to dump that dll with DllSaver.

Enigma Only unpacked exes:
https://www95.zippyshare.com/v/b0258Ft4/file.html

 

Heres ilprotected file cleaned

Test_protected_bodyRestored.exe

Share this post


Link to post
  • 0
wwh1004
Posted (edited)

1. dump ilprotector native runtime

 you can inject a dll to call OpenFileDialog and dump

2. decrypt method body

fix ILProtectorUnpacker's hook, then it works

 

Test.ip.exe.7z

Edited by wwh1004 (see edit history)
  • Thanks 1

Share this post


Link to post
  • 0
Asura
Posted (edited)

@CodeExplorer

Could you please leave the DllSaver download please? Thanks!


 

 

 

 
 
 
 
Edited by Asura (see edit history)

Share this post


Link to post
  • 0
CodeExplorer
4 hours ago, Asura said:

Could you please leave the DllSaver download please? Thanks!

Strange here attachments downloads works ok.
Here is external download link:
https://www3.zippyshare.com/v/fDchNW5P/file.html

  • Like 1

Share this post


Link to post
  • 0
BlackHat
15 hours ago, wwh1004 said:

1. dump ilprotector native runtime

 you can inject a dll to call OpenFileDialog and dump

2. decrypt method body

fix ILProtectorUnpacker's hook, then it works

 

Test.ip.exe.7z 6.04 kB · 2 downloads

Dumping of ILProtector Native -- Done
inject a DLL - Which DLL and Where and How ? 
Fix IL Protector HOOK - Any info about it Brother ???

Share this post


Link to post
  • 0
wwh1004
20 hours ago, Black Hat Anonymous said:

Dumping of ILProtector Native -- Done
inject a DLL - Which DLL and Where and How ? 
Fix IL Protector HOOK - Any info about it Brother ???

Snipaste_2019-06-24_23-32-22.png.2d34ca6156982395c682a7ba7ec20986.png

Code like this. You can copy dlls in OpenFileDialog. If you can't copy dlls (maybe anti dump?), you can use the code like "File.WriteAllBytes(@"I:\Downloads\Yes.dll2", File.ReadAllBytes(@"I:\Downloads\Yes.dll"));".

ILProtector detects the first few bytes of the compiled machine code. You can fake it.

  • Thanks 1

Share this post


Link to post
  • 0
GautamGreat

1. Dumped native dll from Enigma's Virtual Box.

2. Break at OEP of Enigma, and dump binary with Mega Dumper.

3. Put Dumped files in one folder and the unpack with @CodeExplorer's Tool

Here is my unpacked file.

 

unpacked.rar

  • Like 1

Share this post


Link to post
  • 0
zodiac
On 5/15/2019 at 4:47 PM, CodeExplorer said:

After you dump the main exe (.NET) with MegaDumper:

Exception messages:
   Unable to load DLL 'Test32.dll': The specified module could not be found. (Exception from HRESULT: 0x8007007E)

So you got to dump that dll with DllSaver.

Enigma Only unpacked exes:
https://www95.zippyshare.com/v/b0258Ft4/file.html

 

Which options did you use to get the file?
I tried but the file is not correct

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  
×
×
  • Create New...