Jump to content
Tuts 4 You

The Enigma Protector v7.70 (x32 & x64)


Go to solution Solved by TeRcO,

Recommended Posts

Posted

The Enigma Protector v7.70 (x32 & x64)


This is an example program I used to shell The Enigma 7.7. You can shell it, bypass it, PatchHWID, KeyGen to make it run normally. Of course, it would be best if the shell could be peeled off.Have fun!

https://workupload.com/file/EGgppWamMA6

123.png.b4b9e1bc3094e9a6da95616fb12b7cec.png

Cracked:

4561.png.b34701c218701ea618cf8ba5db0cec13.png


 

  • Like 1
Posted
2 hours ago, TeRcO said:

Capture d'écran 2024-11-29 002839.png

Nice.   How to do?

  • Like 2
  • Thanks 1
Posted
13 hours ago, TeRcO said:

(x86)RVA:0000369E : 75 =>EB

well done.  What about x64?

  • Like 1
Posted
1 hour ago, collins said:

well done.  What about x64?

Read here about debbug , about x64 rva adress: 3AEE

 

  • Like 2
  • Thanks 1
Posted
26 minutes ago, azufo said:

Read here about debbug , about x64 rva adress: 3AEE

 

azufo :  thanks man.

QQ20241202001159.jpg.5b0ffaf921da3074d9655408abe02226.jpg

 

  • Like 2
  • Thanks 1
Posted

In fact, 7.6 and 7.7 both have a fatal BUG, I do not use constants. Recently I made a scheme to use constants. The bypass is impossible.If anyone wants to try it, please follow the post and I will upload it here.

  • Like 2
Posted
56 minutes ago, lengyue said:

In fact, 7.6 and 7.7 both have a fatal BUG, I do not use constants. Recently I made a scheme to use constants. The bypass is impossible.If anyone wants to try it, please follow the post and I will upload it here.

let's give a try

  • Like 2
Posted (edited)
11 hours ago, TeRcO said:

let's give a try

Ok,I will makeing it.

 

11 hours ago, TeRcO said:

let's give a try

 

Edited by lengyue
  • Like 2
Posted
4 hours ago, lengyue said:

After having some free Times, I do some steps and don't find anything new.

As always there are no change from it.

Attach key and name to decrypt the section may be I will send a full tutorial for unpacking and patching enigma.

May be the Author will know how their protection works and how to deal wit it.

Have nice day

 

Annotation.png

  • Like 1
  • Thanks 1
Posted
On 12/1/2024 at 9:55 PM, lengyue said:

In fact, 7.6 and 7.7 both have a fatal BUG, I do not use constants. Recently I made a scheme to use constants. The bypass is impossible.If anyone wants to try it, please follow the post and I will upload it here.

LOL are u sure ? again enigma defeated....

Enigma again pached hwid.rar

  • Like 1
  • Thanks 1
Posted (edited)
55 minutes ago, azufo said:

LOL are u sure ? again enigma defeated....

Enigma again pached hwid.rar 6.08 MB · 0 downloads

PatchHWID cannot be prevented, and I haven't come up with an effective way to prevent it yet, but bypass is not feasible. Because the constant cannot be found

Edited by lengyue
You are wonderful. Next time, I will add another method to publish the challenge.
  • Like 1
TRISTAN Pro
Posted (edited)
37 minutes ago, lengyue said:

PatchHWID cannot be prevented, and I haven't come up with an effective way to prevent it yet, but bypass is not feasible. Because the constant cannot be found

Send valid registration name and key otherwise just replace hash with valid and it will work for all pc.

00A20D7F RVA replace esp which valid hash.

00CEA7DA RVa patched the registration manually to nop. 

Edited by TRISTAN Pro
I don't like comment much
  • Like 2
Posted (edited)
1 hour ago, TRISTAN Pro said:

After having some free Times, I do some steps and don't find anything new.

As always there are no change from it.

Attach key and name to decrypt the section may be I will send a full tutorial for unpacking and patching enigma.

May be the Author will know how their protection works and how to deal wit it.

Have nice day

 

Annotation.png

Come on, you can definitely write the patch

Edited by lengyue
I only added a few methods to prevent PatchHWID. This is a myth, if I expose the bottom of it, it should be meaningless. What's your opinion?
  • Like 1
Posted (edited)
34 minutes ago, TeRcO said:

Capture d'écran 2024-12-03 200520.png

The pop-up window of successful registration may not necessarily be a true success, but Mr. @azufo  has successfully found a way. He already knows the bottom line.

Edited by lengyue
Thank you for participating.
  • Like 1
Posted (edited)

By the way, I introduced anti-debugging of vmp in the file.   @azufo  

Edited by lengyue
  • Like 1
Posted
Just now, TRISTAN Pro said:

Send valid registration name and key otherwise just replace hash with valid and it will work for all pc.

00A20D7F RVA replace esp which valid hash.

00CEA7DA RVa patched the registration manually to nop. 

Why delete every time your comment mr.Pro ?

You need valid name and key for enigma target  @lengyue

here........

name: tuts4you

key: 88B7TQYHHHNRKMFFAMXJAS6PW84A9W7PYY8UVS8DYN7PHAMCADQYG797BAPW8P2B9YDZADQAKJBYJMRTJURJ2NEYRXBJSAWUBCL384YD

 

Just now, lengyue said:

PatchHWID cannot be prevented, and I haven't come up with an effective way to prevent it yet, but bypass is not feasible. Because the constant cannot be found

I found rsa key and all info, this is not hard on this new  enigma ;) 

  • Like 1
  • Thanks 1
Sean Park - Lovejoy
Posted
14 minutes ago, azufo said:

Why delete every time your comment mr.Pro ?

You need valid name and key for enigma target  @lengyue

here........

name: tuts4you

key: 88B7TQYHHHNRKMFFAMXJAS6PW84A9W7PYY8UVS8DYN7PHAMCADQYG797BAPW8P2B9YDZADQAKJBYJMRTJURJ2NEYRXBJSAWUBCL384YD

 

I found rsa key and all info, this is not hard on this new  enigma ;) 

@azufo Please teach us something useful.

For example, how to patch hwid and be able to do something as you do.

Regards.

sean.  

Posted (edited)
2 hours ago, azufo said:

Why delete every time your comment mr.Pro ?

You need valid name and key for enigma target  @lengyue

here........

name: tuts4you

key: 88B7TQYHHHNRKMFFAMXJAS6PW84A9W7PYY8UVS8DYN7PHAMCADQYG797BAPW8P2B9YDZADQAKJBYJMRTJURJ2NEYRXBJSAWUBCL384YD

 

I found rsa key and all info, this is not hard on this new  enigma ;) 

Then you can KeyGen it!But constants are still needed。The new version of constants is not easy to find. There is no fixed method, it's not easy for me to find it myself.

x32 RSA:0207D41FA1B8B9F272E46844B2BDC07A40019ADLTLFZ4LLGSS3QNUMVWGSR3J4KR8J8C3N2V78RYYGWMBXKTZZXL6JG5N5D7U8VBKGV8ZRPV2UY7CY48LEVUKAXHSYFRXZMLW438RQBGAZ4RTKUD48ENL88MJNM57N7NJ4T679DSVTK9SESH886DJF5VR925RPZR6NEUY2PRYZYSQ5FX3NJ8ZRQ6XA9S3PRN2FBEZ7CGZKQ6SA2JUZBW5HX63DQWH642CFDN397THZUCZFHVTMT326TSBEXRSH2KY3BQSZQGDTB847Z3HHCTEL3P4EBG8VSU8PQC2BKQUDHJU2GKSNCXRLJFXCUJX73WDPGTPHZAR9QDAWKYRKRLS879H8AQE35L8KWDVXVAJXJZX5E4JHL6NGQQ8DFR7BJFVR568ZQKJA84PCPS2A6KRKJF8U319AEC55ZUV4NTGZ4J5D8ZNCNNWDL2GV7H4Y6VYVTZ5HN63SK7XVSUV3PGKATY35UYVYHRRYC5XPWNJKMLVFZU3S3JFKV7BY5S2MQ2M7TZSWH88SPMUD7DF49LGCQF3X7LCDSJEZ34AD2AC9YUHJVPGY9SY4ZZ3KMXHFT8YRB8DFXTC65VUSM5TM37P7JCQ874LUWXMNMK7MMEKFKSEEH99GAMFE2FMSQVL5QJ6NUCT6LU2YHH99EG9NN6HJ4W6E4FR7GM3F8VU2QSEHB6TURG59LFRYXMQLSMTPUP6KYHHWRMT56C7PSV6WLG2PGTGYYWYACQ5WGVKYCL95KFMSKRGHXQSH467ZW9B4KL4BDSVCB4GACRR4M8NG96ZMF4YJLK9QN3EPXC2V3VH36N3CQN2XPCDPFS19AEZ4TKPQ8E6LWE3UVVSD9BXLVLTNDDKV7HB5DMPRMXSRZM29KZ2XMJR2J9WV3UR2EJ76SCJ5GYE48R78FJC4K8QTU6BTRS4848ZKSZEQWNJSCSSSMNH6JUE5E7SBVE7GFVTLWPDL6ZGBE36NKYB6ANR9DYL3ENGQHQH96Q8KGXRHZR539BCYQ4MXAEXPVWSKW52QSLCVEBTZR2AQDUHWN3UM6FUYK9DMQSNSH299MN9LBZYTJ3GKA2DTMSV76VW8KD9F2SXKLMER7Q5NR8GPYBPRBVT7KKKCKJNLR4BMD47WBHJZUT7DNQ7SJG5FJJSAU8Q5WW44LZ6ENWMZ3S6BJGNG3RCLQV6R6X8LT972EG2X7S9PVF7XUP5VJPVE98WFP3G6LDQVG8Y4RVEMBP5QNR63HC3

x64RSA:020F7ADF029DED21C2F609E165015CF7FBF0CDPUWN3FKC4K3F8P45LCEZ7YDEUSPXFDJL8SYXW22QLDPM3RN5R5HP4E5R7PFUYT6JPCXA9BYBNH3M8B9JG2D4UXQWV3YMRQE927FMKA6GTWFBERBCWH4J8RVW29Y2UH95JNXXFB5W7X5L4REKB6258UU3KF4W3YK85W9BPMYZR2WQNJFS9KXKYJK9TJSAQ2USK5Z3WZBX6SA8H0CDP9RZZ3BWDLXNZXJQWSABRAJ8CJ6YYJ3LZD9HZH49SCP63XXH8LRPEJFUNVNZWD7YJPEZLDY2B3XM9RY2YX7NSPZ77RSG85UV95AE4AHU2TXFVEEMMX4FT7ZTB2NZ4Q3KRNJ65G59TV296DDHQP66UHGAKF7W6KV4SGTRT9FZ8CK3N87Y3CG3LEMJ642AETH68TRCB9CJCYRKK0CDREM2AXD85QEVFPTTLVZ656TYNDVUSKXTWEQ5947CTSRNA5FQLPRHA6WXW6BUT3TYFXBXHKPCWHXKFAEP7SHAGVGRH9BJPYYSH9UX236FYU33Q5DS8BAAXWGW7T7U4MP3XDS3XA9SNEPE8WBRVCQU7R7ETM8HFXAL66S84RPSFLY8KMZ63QJJD2W4HNPT9AMQ9ACRJR6QD2BL9

Edited by lengyue
  • Like 1
TRISTAN Pro
Posted (edited)
19 hours ago, azufo said:

Why delete every time your comment mr.Pro ?

I don't have free times but after check it's the same as always(old).

@lengyue the Constant encryption is 91893BCD.

 

Annotation (2).png

Edited by TRISTAN Pro
Same as old
  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...