Jump to content
Tuts 4 You

VMProtect v3.4.0.1155


Go to solution Solved by BlackHat,

Recommended Posts

Posted (edited)

VMProtect v3.4.0.1155


Try to unpack or alternatively provide a serial. If there is no solution provided by Saturday 11am (GMT+0) I will attach the same without debugger detection.

Protections used:

  • Debugger detection (User-mode + Kernel-mode)
  • Ultra (Mutation + Virtualization)

Disabled protections:

  • Virtual Machine
  • Packer

 

Edited by whoknows
  • Like 2
  • Sad 1
Posted (edited)

they've done a really nice job!
ScreenShot_20200520224109.png.63bc13bb1b9463a8c56ea95bd23ba299.png


valid key:

  Reveal hidden contents

how:

simply you need to figure out how VM read instructions/Eh etc and restore them. devirtualizing all .net targets are the same so try to write a devirtualizer for simple VM and learn how to deal with them.
some other info you can find here & here.

awesome.vmp-devirtualized.exeFetching info...

Edited by Reza-HNA
  • Like 1
CodeExplorer
Posted

@Reza-HNA, with all the respect there isn't any tutorial on how you did it.

 

Posted (edited)

@Reza-HNA shared the solution through PM, restore body method and decrypt the string.

Edited by whoknows
Posted

@CodeExplorer hi, added some info

Teddy Rogers
Posted
  On 5/21/2020 at 12:03 PM, Reza-HNA said:

@CodeExplorer hi, added some info

Expand  

That is still light on with detail and context. It basically links to a tool you used and someone else's post...

Ted.

Posted
  On 5/21/2020 at 8:03 AM, whoknows said:

@Reza-HNA shared the solution through PM, restore body method and decrypt the string.

Expand  

Can you explain bro little bit info regarding removing VMProtect Anti Tamper Remove and restoring Strings ? 

Posted

asking me ? hope @Reza-HNA PM u.

  • Thanks 1
N0P/ribthegreat99
Posted
  On 5/28/2020 at 4:08 PM, BlackHat said:

Can you explain bro little bit info regarding removing VMProtect Anti Tamper Remove and restoring Strings ? 

Expand  

The anti-tamper method is virtualized, so yes you can remove anti-tamper but the app will crash every time because the anti-tamper check method is virtualized.

  • 5 weeks later...
Posted

Please share the solution through PM

vietnguyen09
Posted

You guys are amazing, VMProtect still the best? Which is better between DNGuard and VMProtect?

bruhware2811
Posted

Hey can somebody teach me how to unpack vmprotect for .net? I would be really thankful.

  • 3 weeks later...
  • 3 months later...
Posted

@BlackHat: thank you, it's a nice tutorial! :) 

But could you please fix images in the tutorial, they are very small and unreadable?

Posted (edited)
  On 11/2/2020 at 11:11 PM, kao said:

@BlackHat: thank you, it's a nice tutorial! :) 

But could you please fix images in the tutorial, they are very small and unreadable?

Expand  

 

This is a basic approach example apply on almost all tool protected using vmprotect as suggested by wwh1004 

 

Image 1 - KTxsQsJ.png

Image 2 - qItHHIv.png

 

 

Edited by BlackHat
  • Thanks 1
  • 1 year later...
Posted (edited)

Thank you

Edited by jezani
  • 5 months later...
Posted

l have small exe l needed unpack code.. Posible?

  • 3 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...