Exetools  

Go Back   Exetools > General > Community Tools

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 04-08-2019, 20:53
CodeCracker CodeCracker is offline
VIP
 
Join Date: Jun 2011
Posts: 638
Rept. Given: 38
Rept. Rcvd 568 Times in 215 Posts
Thanks Given: 33
Thanks Rcvd at 3,020 Times in 509 Posts
CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699
Obsidium Olly Scripts

Obsidium Olly Scripts:
First load victim on Olly and execute the ObsidiumOEP.txt script; this will lead to near OEP;
Stolen bytes analyses are inside Obsidium Unpacking (Stolen Code).txt tutorial;
after you get the stolen bytes which have to placed before near entry point.
Finally load ObsidiumIAT.txt script to resolve import table.
Attached Files
File Type: zip Obsidium Scripts.zip (4.4 KB, 41 views)
Reply With Quote
The Following 11 Users Say Thank You to CodeCracker For This Useful Post:
Apuromafo (04-09-2019), Avi_RE (04-09-2019), BAHEK (11-24-2019), conan981 (04-09-2019), Indigo (07-19-2019), niculaita (04-14-2019), sh3dow (04-28-2019), wilson bibe (04-09-2019), yoza (06-13-2019), Zipdecode (04-09-2019)
  #2  
Old 04-09-2019, 18:20
CodeCracker CodeCracker is offline
VIP
 
Join Date: Jun 2011
Posts: 638
Rept. Given: 38
Rept. Rcvd 568 Times in 215 Posts
Thanks Given: 33
Thanks Rcvd at 3,020 Times in 509 Posts
CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699
fixed version of IAT fixer

Attached a fixed version of IAT fixer (now also backup/restore ESP register).
Attached Files
File Type: zip ObsidiumIAT_fixed.zip (1.4 KB, 36 views)
Reply With Quote
The Following User Gave Reputation+1 to CodeCracker For This Useful Post:
ahmadmansoor (04-09-2019)
The Following 9 Users Say Thank You to CodeCracker For This Useful Post:
ahmadmansoor (04-09-2019), Apuromafo (04-09-2019), BAHEK (11-24-2019), bigboss-62 (05-06-2019), Indigo (07-19-2019), niculaita (04-14-2019), sh3dow (04-28-2019), wilson bibe (04-09-2019), yoza (06-13-2019)
  #3  
Old 05-11-2025, 19:37
CodeCracker CodeCracker is offline
VIP
 
Join Date: Jun 2011
Posts: 638
Rept. Given: 38
Rept. Rcvd 568 Times in 215 Posts
Thanks Given: 33
Thanks Rcvd at 3,020 Times in 509 Posts
CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699
New script v3

Attached new script for Obsidium, fixed ObsidiumIAT for dlls files;
Finding OEP for dll files is different: I've break hardware on execute to Rva 1000 - that address was called from OEP; I've returned from that until I found the real OEP.
Obsidium CodeDecrypt.txt - Olly script for decrypting code section.
Attached Files
File Type: txt ObsidiumIAT_v3.txt (6.7 KB, 14 views)
File Type: txt Obsidium CodeDecrypt.txt (2.0 KB, 14 views)
Reply With Quote
The Following User Gave Reputation+1 to CodeCracker For This Useful Post:
Apuromafo (05-12-2025)
The Following 8 Users Say Thank You to CodeCracker For This Useful Post:
Apuromafo (05-12-2025), blue_devil (05-12-2025), MarcElBichon (05-11-2025), SofTw0rm (05-28-2025), tonyweb (05-12-2025), user_hidden (05-11-2025), WRP (05-11-2025), zionoobie (05-12-2025)
  #4  
Old 06-02-2025, 18:54
CodeCracker CodeCracker is offline
VIP
 
Join Date: Jun 2011
Posts: 638
Rept. Given: 38
Rept. Rcvd 568 Times in 215 Posts
Thanks Given: 33
Thanks Rcvd at 3,020 Times in 509 Posts
CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699 CodeCracker Reputation: 500-699
ObsidiumIAT_v4.txt Olly script

ObsidiumIAT_v4.txt Olly script.
Hopefully all bugs was fixed.
Attached Files
File Type: txt ObsidiumIAT_v4.txt (8.6 KB, 7 views)
Reply With Quote
The Following 4 Users Say Thank You to CodeCracker For This Useful Post:
MarcElBichon (06-02-2025), niculaita (06-04-2025), tonyweb (06-02-2025), user_hidden (06-02-2025)
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
simpleJumpLogger and OutsideLogger - Olly debugger scripts CodeCracker Community Tools 0 12-19-2022 20:45
Safengine Olly scripts CodeCracker Community Tools 14 04-19-2019 09:50
OllyScript scripts for FSG 1.0 and 2.0 TQN General Discussion 1 05-26-2004 20:14


All times are GMT +8. The time now is 02:13.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( 1998 - 2025 )