Exetools  

Go Back   Exetools > General > General Discussion

Notices

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #21  
Old 10-31-2017, 21:49
Benten Benten is offline
Friend
 
Join Date: Sep 2017
Location: Oh that's personal stuff, Don't want MI6 at my Mom's face
Posts: 24
Rept. Given: 0
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 12
Thanks Rcvd at 13 Times in 9 Posts
Benten Reputation: 3
TrapZero FFF Armadillo 9 x64 Manual Unpacking ENG by Ben

As promised here is the x64 IAT Elimination - Manual Unpacking
This is actually the FFF Tutorial. I've just added a much needed video to it.

Also I've identified some patterns to make the search easy. There are crashes so the dump is not perfect, but the unpacking works fine. May be locked features are crashing the dump, as Mr. Exodia puts it, needs more work I guess. I can't do brute forcing, we don't have any PC that good around the Coffee shop.

Thanks and Respects,

Last edited by Benten; 11-01-2017 at 04:55. Reason: Respects to Mr.Exodia, Mr.Smiling Wolf, TrapZero/FFF, Exetools Family & Regards to my Friend abhi93696
The Following User Says Thank You to Benten For This Useful Post:
abhi93696 (11-01-2017)
 

Tags
armadillo, armadillo unpacking, import elimination, tutorial request


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 05:40.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )