Jump to content
Tuts 4 You

The Enigma Protector x64 v7.4 (HWID Lock)


Recommended Posts

Sean Park - Lovejoy
Posted

The Enigma Protector x64 v7.4 (HWID Lock)


Two simple Win x64 GUI applications protected using Enigma x64 v7.4.

Challenge is to;

  1. bypass the hardware ID lock;
  2. unpack the application.

Let us go together to solve this issue.


  • Submitter
    The Binary Expert
  • Submitted
    06/17/2024
  • Category

 

  • Like 3
  • 5 weeks later...
lengyue
Posted

If you provide the key, it will be even more perfect

3.png.d9d47a82eea75d92b45571b2d77cd0b1.png81.png.97cacaeeaaed76353c8de59622b34151.pngQQ20240720184712.png.3effaa5622e88f9a7c7da9c952a55f55.png

 

Win64GUI-Enigma v.7.40 uses constant encryption and cannot be bypassed without a valid key

4.png.57eb5d48e7ab8198b0aed5f019a5ef21.png

QQ截图20240720183621.png

  • Like 1
Sean Park - Lovejoy
Posted
5 hours ago, lengyue said:

If you provide the key, it will be even more perfect

3.png.d9d47a82eea75d92b45571b2d77cd0b1.png81.png.97cacaeeaaed76353c8de59622b34151.pngQQ20240720184712.png.3effaa5622e88f9a7c7da9c952a55f55.png

 

Win64GUI-Enigma v.7.40 uses constant encryption and cannot be bypassed without a valid key

4.png.57eb5d48e7ab8198b0aed5f019a5ef21.png

QQ截图20240720183621.png

@lengyue So you could not bypass the 2 protected ones?

Password : www.tuts4you.com

Regards.

sean.

  • Like 1
lengyue
Posted
59 minutes ago, The Binary Expert said:

@lengyue So you could not bypass the 2 protected ones?

Password : www.tuts4you.com

Regards.

sean.

uses constant encryption and cannot be bypassed without a valid key,I can't bypass it

  • Like 1
Sean Park - Lovejoy
Posted (edited)
41 minutes ago, lengyue said:

uses constant encryption and cannot be bypassed without a valid key,I can't bypass it

@lengyue Try this please.

Enigma x64 Protected and Keymaker.zip

Regards.

sean.

Edited by The Binary Expert
  • Like 1
gzfuqun111
Posted

RVA:D05BE7   mov  rax,1

RVA:38A1E0   encryption constant

  • Thanks 1
Sean Park - Lovejoy
Posted (edited)
17 hours ago, gzfuqun111 said:

RVA:D05BE7   mov  rax,1

RVA:38A1E0   encryption constant

@gzfuqun111

screenshot-6.png.7528182f445bd3f6a8aec7e42519b21a.png

Regards.

sean.

Edited by The Binary Expert
  • Like 1
Posted

RVA:D05BE7   mov  rax,1

RVA:38A1E0   encryption constant 

Your need to modify the  above two  parts.

  • Like 1
collins
Posted
1 hour ago, fq3803 said:

RVA:D05BE7   mov  rax,1

RVA:38A1E0   encryption constant 

Your need to modify the  above two  parts.

Cousin, could you please provide a tutorial.

  • Like 1
lengyue
Posted (edited)
On 7/22/2024 at 9:29 PM, collins said:

Cousin, could you please provide a tutorial.

Jump to module baseaddress+RVA, Set hardware execution breakpoints ,run, set rax==1 run.OK!You will looking.

 

@The Binary Expert

Win64GUI_Enigma v.7.40

2.png.b7c13d1b95bd403d132b08d6559fda54.png

Win64GUI_Enigma v.7.40_encrypted

Without the correct registration code, I cannot crack it~!

RSA.png.1d7aa88eeaf83e54173f4ecb35ec1c7a.png

Edited by lengyue
  • Thanks 1
TRISTAN Pro
Posted
5 hours ago, lengyue said:

Jump to module baseaddress+RVA, Set hardware execution breakpoints ,run, set rax==1 run.OK!You will looking.

 

@The Binary Expert

Win64GUI_Enigma v.7.40

2.png.b7c13d1b95bd403d132b08d6559fda54.png

Win64GUI_Enigma v.7.40_encrypted

Without the correct registration code, I cannot crack it~!

RSA.png.1d7aa88eeaf83e54173f4ecb35ec1c7a.png

May be need to brute force to get hash decryption without combination of valid data as name and key.

  • Like 1
Sean Park - Lovejoy
Posted (edited)
52 minutes ago, TRISTAN Pro said:

May be need to brute force to get hash decryption without combination of valid data as name and key.

@TRISTAN Pro  Download this package which is included of the keymaker.

52 minutes ago, TRISTAN Pro said:

HWID : C360B-83DD5-188BB-97BB6-115FD-C7C8F-2F465-E76A7

Name : tuts4you.com

Key : LN6Q-QRGH-4B2V-64DU-AHQC-GACW-PCL8-6MKK-DU8L-NRTK-Y8WN-3F4A-XK3D-7WW2-54JL-WCMQ-L5MZ-QXB5-9EKU-UAGJ-F6BZ-KFCG-HPFN-4F3K-H6EU-2GGN-PZ55-QX49-ULGX-YXX7-HMNF-TNR8-ZS7D-2UH9-W3L2-PWM9-44E2-5B4A-6TDN-HCYD-6VER-W7LS-JMGL-HK8V-AQCP-KUPZ-JMFD-QARC-5QY8Q

Regards.

sean.

Edited by The Binary Expert
  • Like 3
  • 1 month later...
  • 3 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...