Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

Posted

NiggaEX

Unpack and provide a overview of how you did it and what tools were used.

File Information

Submitter DarkShadow

Submitted 02/13/2022

Category UnPackMe (.NET)

View File

NiggaEX

  • 3 weeks later...

you did not change anything, whats cool about it ? the protector Name?

  • 1 month later...
  • Author
On 2/28/2022 at 4:20 PM, Mr-Toms said:

you did not change anything, whats cool about it ? the protector Name?

NiggaEX is a ConfuserEx modification with the following changes;

Renamed (types, methods, fields, resources)

String enc

Control flow

  • 2 weeks later...

 

Control flow is alredy includet in the normal confuserEx ergo not new function same for string enc is ther to alredy same for resource and the orther stuff you mention that you attet it that stuff is alredy includet in each cunfuserEx.

HM what should i say xd :

of curse its not komplett devizert but the standart tools work so far

Spoiler

image.png.ea0d9a3df875e9caf4d8ae81b738d351.png

Edited by Underground

you need to know the right order to unpack this 

this is the order i do after decompress and remove anti tamper

and the unpacked file is not de4doted yet , and the entrypoint still missing 

image.png.7e2dee21d1c5e7d8ccaf3f0c133aa064.png

NiggaEx_Decompressed_NoCfex.exe

Edited by Mr-Toms

  • Author
On 4/30/2022 at 11:33 AM, Accede said:

 

Control flow is alredy includet in the normal confuserEx ergo not new function same for string enc is ther to alredy same for resource and the orther stuff you mention that you attet it that stuff is alredy includet in each cunfuserEx.

HM what should i say xd :

of curse its not komplett devizert but the standart tools work so far

  Reveal hidden contents

image.png.ea0d9a3df875e9caf4d8ae81b738d351.png

It's not the same string encryption & not same renamer

i've solved this but i dont know why moderator didnt approved my comments

  • 2 weeks later...
  • Author
On 5/11/2022 at 5:46 AM, Mr-Toms said:

i've solved this but i dont know why moderator didnt approved my comments

Check the rules 

  • 5 months later...

image.png.17e461fd15c0ff17bec9df5ba6a49956.png

There's not much to describe about the unpacking steps, I just dumped it and made a de-obfuscator for it.

Unpacked.exe

Edited by SychicBoy

Well, what did you use to dump it and can you show the deobfuscator? ;)

On 11/7/2022 at 10:14 PM, deepzero said:

Well, what did you use to dump it and can you show the deobfuscator? ;)

Steps:
1-Execute the target file
2-Open "ExtremeDumper-x86" and select AntiDump mode from Options>DumpType. On processes list right click on the target process and select View Modules option and find the <<EmptyName>> from the modules list and dump it.
3-Open the dumped file in dnSpy find the entrypoint then right click on the assembly module and set the entrypoint of the module then save the changes.
4-Use "ConfuserEx-Unpacker" to get rid of cflow, call proxy, etc...
5-Use "Size and Mathematical Fixer" to get rid of sizeof's and mathematical obfuscation.
6-Use "de4dot" to rename symbols.
7-Now you should do the rest yourself: (clean if cflow, fix string/int proxy, decrypt strings).

Tools.zip

Edited by SychicBoy

filepath -c corruptFile 
filepath -c vv
filepath -c dd

-c corruptFile will make nop cflow but file will not run , because i am new;

-c vv will show u the process

-c dd [manual :: Class removing process disable ]

use only -vv will de4dot args as usual 

NSCL restored fixed 

 

or simple just drop this target 

2015Unpacker.zip

2015UnpackerM.zip

Edited by Only_Islams_The_Rifht_Path
fixed bugs and remove chain M

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.