Jump to content
Tuts 4 You

Easy CrackMe (YeetFuscator)


Go to solution Solved by BlackHat,

Recommended Posts

Posted (edited)

Easy CrackMe (YeetFuscator)


Language: C#(.Net)

Goal: to get the key of obfuscated file

Key on the screenshot is wrong, you have to crack this CrackMe and send key with tutorial on how did you do that.


 

Edited by Alex0
Forgot the name of protector
Posted

20 Seconds

79320480-148247987-UXNEIFN

  • Solution
Posted

As It is a Crack Me and the Goal is to get the key of obfuscated file

So I am going to find the Key without actually Unpacking It.

Methodology -

  Quote

 

  • Run the software. 
  • Open the Process Hacker.
  • Enter anything in the TextBox and It will show an Error.
  • Check for that in Memory Strings and You will find out the Correct Key just near to it.

 

Expand  

Valid Key -

  Reveal hidden contents

Image -

  Reveal hidden contents

 

  • Like 2
tarequl.hassan
Posted
  On 7/2/2021 at 3:20 PM, BlackHat said:

As It is a Crack Me and the Goal is to get the key of obfuscated file

So I am going to find the Key without actually Unpacking It.

Methodology -

Valid Key -

  Reveal hidden contents

Image -

  Reveal hidden contents

 

Expand  

Hello Blackhat

Can you share your Process Hacker?

 

Thanks

KanohAgito
Posted
  On 7/2/2021 at 5:49 PM, tarequl.hassan said:

Hello Blackhat

Can you share your Process Hacker?

 

Thanks

Expand  

lol lol why you even here !!! search in google !!!

  • Haha 1
  • Sad 1
Posted (edited)
  On 7/2/2021 at 5:49 PM, tarequl.hassan said:

Hello Blackhat

Can you share your Process Hacker?

 

Thanks

Expand  

Hello, tarequl.hassan!

I think he used this https://processhacker.sourceforge.io/downloads.php

To get straight to the Memory Strings you should do folowing:

1. Open obfuscated app

2. Open process hacker

3. Find your process in Process Hacker and right click on it

4. Select "Properties" and navigate to tab called "Memory"

5. You will see button in top-right called "Strings..."

That's it, I hope it helped. Have a nice day!

Edited by Alex0
  • Thanks 1
tarequl.hassan
Posted
  On 7/2/2021 at 7:00 PM, Alex0 said:

Hello, tarequl.hassan!

I think he used this https://processhacker.sourceforge.io/downloads.php

To get straight to the Memory Strings you should do folowing:

1. Open obfuscated app

2. Open process hacker

3. Find your process in Process Hacker and right click on it

4. Select "Properties" and navigate to tab called "Memory"

5. You will see button in top-right called "Strings..."

That's it, I hope it helped. Have a nice day!

Expand  

Thanks mate for the support with the procedure. 

 

Have a nice day.

  • Like 1
  • 3 years later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...