Posted April 2, 20214 yr Hello everybody, this is my first post in this forum... I have been trying to learn devirtualization for protectors like VMProtect or Themida. But I coudn't find much information. I was hoping someone here can point me to the right direction, recommend me any book or literature. Thanks in advance.
April 2, 20214 yr Here's a good tutorial about static devirtualization of a simple VM: https://www.msreverseengineering.com/blog/2018/1/23/a-walk-through-tutorial-with-code-on-statically-unpacking-the-finspy-vm-part-one-x86-deobfuscation http://www.msreverseengineering.com/blog/2018/1/31/finspy-vm-part-2-vm-analysis-and-bytecode-disassembly http://www.msreverseengineering.com/blog/2018/2/21/finspy-vm-unpacking-tutorial-part-3-devirtualization
May 20, 20214 yr Check out this excellent blogpost about devirtualizing VMP2: https://back.engineering/17/05/2021/
May 20, 20214 yr Defeating Nested Virtualization with Miasm - FCSC21 CTF VMV https://mrt4ntr4.github.io/FCSC21-CTF-VMV/
Create an account or sign in to comment