Exetools  

Go Back   Exetools > General > General Discussion

Notices

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 10-31-2017, 21:49
Benten Benten is offline
Friend
 
Join Date: Sep 2017
Location: Oh that's personal stuff, Don't want MI6 at my Mom's face
Posts: 24
Rept. Given: 0
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 12
Thanks Rcvd at 13 Times in 9 Posts
Benten Reputation: 3
TrapZero FFF Armadillo 9 x64 Manual Unpacking ENG by Ben

As promised here is the x64 IAT Elimination - Manual Unpacking
This is actually the FFF Tutorial. I've just added a much needed video to it.

Also I've identified some patterns to make the search easy. There are crashes so the dump is not perfect, but the unpacking works fine. May be locked features are crashing the dump, as Mr. Exodia puts it, needs more work I guess. I can't do brute forcing, we don't have any PC that good around the Coffee shop.

Thanks and Respects,

Last edited by Benten; 11-01-2017 at 04:55. Reason: Respects to Mr.Exodia, Mr.Smiling Wolf, TrapZero/FFF, Exetools Family & Regards to my Friend abhi93696
The Following User Says Thank You to Benten For This Useful Post:
abhi93696 (11-01-2017)
  #2  
Old 11-01-2017, 08:11
SmilingWolf SmilingWolf is offline
Family
 
Join Date: Dec 2014
Posts: 43
Rept. Given: 4
Rept. Rcvd 97 Times in 24 Posts
Thanks Given: 4
Thanks Rcvd at 149 Times in 30 Posts
SmilingWolf Reputation: 97
Quote:
Originally Posted by Benten View Post
May be locked features are crashing the dump
That's not how Secure Sections work. If the program works in trial mode but not once unpacked something got messed up in the process. Most likely it's the splices that haven't been fixed correctly. You can try to simply redirect them to the .pdata section instead of resolving/fixing them. Less likely it's because of some CALL or JMP to imports that for one reason or the other didn't make it into the final dump.

Quote:
Originally Posted by Benten View Post
I can't do brute forcing, we don't have any PC that good around the Coffee shop.
Code:
Global Information:
   TimeStamp : 522B6164
 First DWORD : BEB12B6C
  Project ID : EZ CD Audio Converter 5
     Website : http://www.poikosoft.com/buy.html
      Magic1 : A99D3A69
      Magic2 : 185F
        Salt : DDFD006F
  Crypt Seed : 3D1F87D1 (0xE, 0xF, 0x4, 0x4)

Public Certificate Information:
  Short V3 Level 10:
    Chk : 2C0F3520
    Sym : 2B7D0D69
  BaseP : 438743756 (Size=4F, Diff=2F67, MD5=32F5621D)
  Pub.X : 5166803264428898532848136302152315
  Pub.Y : 5885292780640973861494979822117782

  Short V3 Level 10:
    Chk : F4A58BED
    Sym : D25882FE
  BaseP : 2707316665 (Size=50, Diff=2FBC, MD5=EB410984)
  Pub.X : 9572786991591576323293497288923141
  Pub.Y : 7813891883224157983281644193935444

  Short V3 Level 10:
    Chk : D310A5F2
    Sym : F9B0ABB5
  BaseP : 3073286976 (Size=50, Diff=3012, MD5=5DD8378B)
  Pub.X : 8853314056135967505699477416912929
  Pub.Y : 2273504409043285102220298435426270

  Short V3 Level 10:
    Chk : 76B6BB27
    Sym : AA65E8AC
  BaseP : 3279749701 (Size=4F, Diff=3068, MD5=81777B0F)
  Pub.X : 3277174474704060691137745527117117
  Pub.Y : 308731733377103543808919722499418

Intercepted Libraries:
  -*
GIV's script v0.1 can be found on tuts4you just like *shameless plug* my Armadillo Factotum script. Never ask anyone but the original poster to mirror an attachment. It's against the rules.
The Following 2 Users Say Thank You to SmilingWolf For This Useful Post:
Benten (11-01-2017), tonyweb (11-04-2017)
Closed Thread

Tags
armadillo, armadillo unpacking, import elimination, tutorial request

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



All times are GMT +8. The time now is 21:02.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )