Jump to content
Tuts 4 You

VMProtect v3.5.0.1213


Go to solution Solved by BlackHat,

Recommended Posts

Posted (edited)

VMProtect v3.5.0.1213


Try to unpack or alternatively provide a serial. If there is no solution provided by Saturday 11am (GMT+0) I will attach the same without debugger detection.

Protections used:

Debugger detection (User-mode + Kernel-mode)

Ultra (Mutation + Virtualization)


 

Edited by whoknows
  • Like 4
  • 3 weeks later...
Posted (edited)

First step :)

Used DnSoy to dump it

 

dump.JPG

Edited by sirp
Posted

it seems No ways 🙄 Vmp for .net is the best

tungtruong20xx
Posted
  On 8/23/2020 at 2:51 PM, sirp said:

First step :)

 

 

dump.JPG

Expand  

can u help me solution :( 

Posted (edited)

Here is one of the solutions:

  Reveal hidden contents

It uses cryptography to decrypt a string provided withing the key,key also contains RV and salt,which I both set to all \0,if it succeeds then it prints hi <DecrytpedString> thanks for registering,if it fails it prints invalid serial

 

Edit:

Decrypted Validate function:

  Reveal hidden contents

 

Edited by BataBo
  • Like 1
Posted
  On 8/23/2020 at 2:51 PM, sirp said:

First step :)

 

 

dump.JPG

Expand  

clean mutations to fully complete

  • Haha 1
tungtruong20xx
Posted

can u help me solotion unpack this vmprotect 

Posted (edited)

Fun challenge. I went for finding just the key algorithm rather than fully devirtualizing, but the code is pretty clear. Here some sample keys:

  Reveal hidden contents

Approach:

  Reveal hidden contents

Keygen.7zFetching info...

Edited by Washi
  • Like 3
  • Thanks 8
Posted
  On 9/2/2020 at 6:44 PM, Washi said:

Fun challenge. I went for finding just the key algorithm rather than fully devirtualizing, but the code is pretty clear. Here some sample keys:

  Reveal hidden contents

Approach:

  Reveal hidden contents

Keygen.7z 7.15 kB · 7 downloads

Expand  

Are you sure it's correct,the key isn't 'tetris' the key is 'duck',keys provided above don't work.

Posted

I think Washi's solution is actually for 

 

At least, the provided keys work for that executable. :)

 

  • Like 1
Posted (edited)
  On 9/3/2020 at 10:48 AM, BataBo said:

Are you sure it's correct,the key isn't 'tetris' the key is 'duck',keys provided above don't work.

Expand  

Whoops you are completely right, I posted my reply to the wrong vmp crackme/unpackme challenge thread. @whoknows has made two threads :D

This one is actually easier, since code is pretty much readable (after you dumped it from memory that is). And yea, the password for this one is indeed "duck" rather than tetris. :)

 

Edited by Washi
  • Like 2
tungtruong20xx
Posted

Hey Guy
Can u help me unpack this method

Sorry my english is bad

.exe and runtime.dll

image.png

image.png

Posted

just packer, mutation and refh proxy.

  • Thanks 1
  • 3 weeks later...
Posted

"Ultra (Mutation + Virtualization)"

This was never Virtualized...

  • 4 weeks later...
  • 2 weeks later...
  • 3 months later...
Posted (edited)
  Reveal hidden contents

Download: https://s4.dosya.tc/server13/tkpa2e/awesome.vmp_clean.exe.html

Key: HlgoynfyxFiMv94XScOTlJA65DTJrPd9pRY0zI3mKyO+IOunYkFdYWn6lGCufjKvVLrzZ94ivnJgqyVgvfjKpSyN4ImrVY/Bl5XU7+ne859RySqgyX919rcgIs6mk6OK

SS

rlXVEi.png

 

Edited by Leopar36
  • Thanks 1
  • Haha 1
  • 3 weeks later...
bruhware2811
Posted
  On 2/12/2021 at 8:56 PM, Leopar36 said:
  Reveal hidden contents

Download: https://s4.dosya.tc/server13/tkpa2e/awesome.vmp_clean.exe.html

Key: HlgoynfyxFiMv94XScOTlJA65DTJrPd9pRY0zI3mKyO+IOunYkFdYWn6lGCufjKvVLrzZ94ivnJgqyVgvfjKpSyN4ImrVY/Bl5XU7+ne859RySqgyX919rcgIs6mk6OK

SS

rlXVEi.png

 

Expand  

How did you clean it so well? Do you have any tools?

  • 6 months later...
Posted
  On 11/3/2020 at 8:05 AM, BlackHat said:

awesome.vmp35_cracked.exe 493 kB · 29 downloads

Every other portion of VMP is removed including CRC etc check. But still it will not run until we fix Delegates. It is still left 

  Reveal hidden contents

rxIPgz1.png

 

Expand  

I forgot this Post btw It was fine except Delegates which can be fixed easily.

awesome_done.exeFetching info...

  • 1 month later...
Posted

hey guys

 

i know you're all too busy with life for arranging a tutorial but could you please at least say the steps you took or refer to other pertaining tutorials/papers?

Posted

Have to agree with the posts above. Most of the solutions here are not really tutorials. They are mostly just a binary / source code that is cleared without any explanation of how it is done, which is what tuts4you I believe is meant to be about.

  • Like 2
  • 1 month later...
  • Solution
Posted

How to Unpack this VMProtect 3.5 Challenge - 2022/01/10 by @BlackHat

Tutorial :

  Reveal hidden contents

Video Tutorial : 

 

Best Regards

BlackHat

awesome.vmp35_BH_unp.exeFetching info...

  • Like 7
  • Thanks 5
Posted
  On 1/19/2022 at 7:59 PM, BlackHat said:

Bu VMProtect 3.5 Mücadelesi Nasıl Açılır - 2022/01/10 tarafından @Siyah şapka

öğretici :

  Reveal hidden contents

Video Eğitimi : 

 

Saygılarımla

Siyah şapka

harika.vmp35_BH_unp.exe 95 kB · 2 indirme

Expand  

 

Hello, can you upload the tools in the tutorial, thank you very much, you did a great job.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...