Exetools  

Go Back   Exetools > General > Community Tools

Notices

Reply
 
Thread Tools Display Modes
  #136  
Old 04-01-2015, 12:48
EHS4N EHS4N is offline
Family
 
Join Date: Feb 2012
Posts: 40
Rept. Given: 14
Rept. Rcvd 56 Times in 21 Posts
Thanks Given: 16
Thanks Rcvd at 33 Times in 12 Posts
EHS4N Reputation: 57
Modified de4dot it now supports the latest version of .NET Reactor 4.9.7.0
all credits to SHADOW785

http://i58.tinypic.com/alq0xv.png

Code:
http://rghost.net/6ll86FcYf
BR

Last edited by EHS4N; 04-01-2015 at 13:04.
Reply With Quote
The Following User Gave Reputation+1 to EHS4N For This Useful Post:
niculaita (04-01-2015)
The Following 4 Users Say Thank You to EHS4N For This Useful Post:
leetone (04-02-2015), niculaita (04-01-2015), NoYes (04-04-2015)
  #137  
Old 04-01-2015, 16:45
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,115
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 108
Thanks Rcvd at 216 Times in 124 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
If there was a special 'VIP' version of de4dot, I haven't seen anywhere.

Git
Reply With Quote
  #138  
Old 04-02-2015, 03:01
leetone's Avatar
leetone leetone is offline
Family
 
Join Date: Apr 2014
Posts: 144
Rept. Given: 41
Rept. Rcvd 31 Times in 20 Posts
Thanks Given: 21
Thanks Rcvd at 50 Times in 36 Posts
leetone Reputation: 34
Quote:
Originally Posted by Git View Post
If there was a special 'VIP' version of de4dot, I haven't seen anywhere.

Git
Good. That's how it should be. This is the post that prompted me to say that:

Quote:
Originally Posted by giv View Post
For those who does not know all start when a private version was leaked from VIP area by a VIP of Exetools.

Don't worry.
Common obfuscations will always have a tool coded for deobfuscate.
Or you can start to learn I.L. and maybe make your own deobfuscator or modify de4dot to adapt to new requirements.

Anyways, I'm gonna check out this 4.9 reactor modded version posted above...very excited!
Reply With Quote
  #139  
Old 04-02-2015, 16:39
Git's Avatar
Git Git is offline
Old Git
 
Join Date: Mar 2002
Location: Torino
Posts: 1,115
Rept. Given: 220
Rept. Rcvd 265 Times in 157 Posts
Thanks Given: 108
Thanks Rcvd at 216 Times in 124 Posts
Git Reputation: 200-299 Git Reputation: 200-299 Git Reputation: 200-299
"leaked from VIP area". This is precisely what I mean. There is no special version in the VIP area, and I don't recall ever seeing one there. I don't know where giv is getting his info.

Git
Reply With Quote
  #140  
Old 04-27-2015, 20:50
daqstar's Avatar
daqstar daqstar is offline
Family
 
Join Date: Jun 2006
Posts: 97
Rept. Given: 34
Rept. Rcvd 59 Times in 22 Posts
Thanks Given: 37
Thanks Rcvd at 31 Times in 17 Posts
daqstar Reputation: 59
de4dot v3.1.41592.3405


Here is the latest Release:
Attached Files
File Type: rar de4dot v3.1.41592.3405.rar (843.1 KB, 63 views)
__________________
0z0n3
Reply With Quote
The Following User Says Thank You to daqstar For This Useful Post:
TechLord (04-27-2015)
  #141  
Old 04-27-2015, 23:52
NoYes NoYes is offline
Friend
 
Join Date: Jul 2014
Posts: 7
Rept. Given: 18
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 8
Thanks Rcvd at 0 Times in 0 Posts
NoYes Reputation: 0
difference

Quote:
Originally Posted by daqstar View Post

Here is the latest Release:
Hello daqstar,
Can you tell us what's the difference between your post version and the 0xd4d's last release version, because the files version are the same.
Reply With Quote
  #142  
Old 04-28-2015, 03:02
sendersu sendersu is offline
VIP
 
Join Date: Oct 2010
Posts: 1,067
Rept. Given: 332
Rept. Rcvd 223 Times in 115 Posts
Thanks Given: 235
Thanks Rcvd at 513 Times in 288 Posts
sendersu Reputation: 200-299 sendersu Reputation: 200-299 sendersu Reputation: 200-299
Quote:
Originally Posted by EHS4N View Post
Modified de4dot it now supports the latest version of .NET Reactor 4.9.7.0
all credits to SHADOW785

http://i58.tinypic.com/alq0xv.png

Code:
http://rghost.net/6ll86FcYf
BR
does not recover following binary (supposing it is a new ver of .net reactor)

just says a ton of mesages like
.........
WARNING: Could not deobfuscate method 06000004. Hello, E.T.: System.ArgumentOutOfRangeException
.........
ERROR: Local/arg index doesn't fit in a UInt16
ERROR: Local/arg index doesn't fit in a UInt16
ERROR: Error calculating max stack value
ERROR: Local/arg index doesn't fit in a UInt16
ERROR: Local/arg index doesn't fit in a UInt16
..........


not sure if someone is interesting in reversing.....
Reply With Quote
  #143  
Old 04-28-2015, 03:46
ahmadmansoor's Avatar
ahmadmansoor ahmadmansoor is offline
Coder
 
Join Date: Feb 2006
Location: Syria
Posts: 1,045
Rept. Given: 509
Rept. Rcvd 373 Times in 142 Posts
Thanks Given: 336
Thanks Rcvd at 407 Times in 119 Posts
ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399 ahmadmansoor Reputation: 300-399
Yes it is new .net reactor .
I have Target protected .but it is for x64
__________________
Ur Best Friend Ahmadmansoor
Always My Best Friend: Aaron & JMI & ZeNiX
Reply With Quote
  #144  
Old 04-29-2015, 10:49
speedboy
 
Posts: n/a
Where is the special 'VIP' version of de4dot?
Reply With Quote
  #145  
Old 04-29-2015, 19:15
mr.exodia mr.exodia is offline
Retired Moderator
 
Join Date: Nov 2011
Posts: 784
Rept. Given: 492
Rept. Rcvd 1,122 Times in 305 Posts
Thanks Given: 90
Thanks Rcvd at 711 Times in 333 Posts
mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299
Quote:
Originally Posted by speedboy View Post
Where is the special 'VIP' version of de4dot?
There is none as mentioned various times in the thread.
Reply With Quote
  #146  
Old 05-16-2015, 17:54
Sir.V65j Sir.V65j is offline
Friend
 
Join Date: Oct 2010
Posts: 66
Rept. Given: 35
Rept. Rcvd 32 Times in 15 Posts
Thanks Given: 68
Thanks Rcvd at 54 Times in 21 Posts
Sir.V65j Reputation: 32
Quote:
Originally Posted by ιvancιтooz
Today I bring all this de4dot, who works for the latest versions of CryptoObfuscator, PhoenixProtector and NetReactor , I hope you like it, if they have a problem tell me in the comments and I'll try solve.





Crypto With de4dot 3.4.1 without modded: http://prntscr.com/75gvxp

Crypto With this de4dot: http://prntscr.com/75gx1x



Target With CryptoObfuscator Build 150203: http://www74.zippysh...v3LGt/file.html

Target Cleaned With this de4dot: http://www14.zippysh...v849N/file.html



Credits to :

-SHADOW_UA for help me on .NetReactor

-TheProxy for PhoenixProtector and OrangeHeap
source Link
Reply With Quote
The Following User Says Thank You to Sir.V65j For This Useful Post:
NoYes (05-16-2015)
  #147  
Old 05-16-2015, 22:04
mdj's Avatar
mdj mdj is offline
♀♥♂KAMDEV♂♥♀
 
Join Date: Nov 2011
Posts: 159
Rept. Given: 141
Rept. Rcvd 139 Times in 49 Posts
Thanks Given: 79
Thanks Rcvd at 28 Times in 15 Posts
mdj Reputation: 100-199 mdj Reputation: 100-199
Quote:
Originally Posted by Sir.V65j View Post
Updated:

- new support added to orangeheap
https://mega.co.nz/#!rRsj1b7S!nW9HOO...x9ykimkDV7ybVY
Reply With Quote
  #148  
Old 05-17-2015, 14:12
leetone's Avatar
leetone leetone is offline
Family
 
Join Date: Apr 2014
Posts: 144
Rept. Given: 41
Rept. Rcvd 31 Times in 20 Posts
Thanks Given: 21
Thanks Rcvd at 50 Times in 36 Posts
leetone Reputation: 34
Hey guys, news on 5/16/2015
mr. EXODIA opened a new repository on github it's a fork of 0xd4d/de4dot -- and can be found here: https://github.com/mrexodia/de4dot

What is it?
Well, as of right now there are 2 branches. 'master' which is inline with the de4dot upstream, or 'dynamic-loading' which has 7-9 commits beyond master:
http://i.imgur.com/aM8ZoKG.png

Really good stuff....
Reply With Quote
The Following User Says Thank You to leetone For This Useful Post:
ahmadmansoor (05-18-2015)
  #149  
Old 05-17-2015, 19:47
Hypnz Hypnz is offline
Friend
 
Join Date: Oct 2014
Posts: 48
Rept. Given: 6
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 258
Thanks Rcvd at 27 Times in 21 Posts
Hypnz Reputation: 1
Well done Mr.Exodia
Now de4dot has public sources as supposed to be
Reply With Quote
  #150  
Old 05-17-2015, 19:50
mr.exodia mr.exodia is offline
Retired Moderator
 
Join Date: Nov 2011
Posts: 784
Rept. Given: 492
Rept. Rcvd 1,122 Times in 305 Posts
Thanks Given: 90
Thanks Rcvd at 711 Times in 333 Posts
mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299 mr.exodia Reputation: 1100-1299
@leetone: The new branch of interest is dynamic_loading_fix, which allows for dynamic deobfuscator module loading (making the spread of all these modified versions unnecessary since you can just give the dll required).
Reply With Quote
The Following 2 Users Say Thank You to mr.exodia For This Useful Post:
ahmadmansoor (05-18-2015), mdj (05-18-2015)
Reply

Tags
de4dot, deobfusacator

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[C#] De4Dot GUI V0K3 Source Code 2 04-17-2015 06:07


All times are GMT +8. The time now is 08:08.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2024 )