Сейчас на форуме: rmn (+1 невидимый пользователь) |
![]() |
eXeL@B —› WorldWide —› Unpacking help (Execryptor) |
Посл.ответ | Сообщение |
|
Создано: 06 января 2008 21:00 · Поправил: waliska · Личное сообщение · #1 Hi, this is not the best first post but a starting. The target is http://rapidshare.com/files/81773947/bot.rar.html http://rapidshare.com/files/81773947/bot.rar.html originaly it's packed with themida. it got unpacked+inlined and packed again with execryptor as long as i can trust peid and stuff. props go out to thejhorse for filling this releas up with some nasty stuff and the real props go out to sunbeam for removing all that nasty stuff and cracking it propably+releasing it to all. this bot is detected but i want to give a try to make it undetected. The problem is that i'm not that good unpacking that hardcore stuff :/ maybe someone got the time and is willing to do this for me. the other problem is that this bot is not going to be updatet anymore :/ so the goal is to provide me a a clean as possible file+runable so that i can go on to try get it undetected. thx in advance wali ![]() |
|
Создано: 06 января 2008 21:28 · Личное сообщение · #2 |
|
Создано: 06 января 2008 21:55 · Поправил: waliska · Личное сообщение · #3 |
|
Создано: 07 января 2008 06:49 · Личное сообщение · #4 GameGuard blacklists certain characteristics of a threat. Even if you get it 100% unpacked, you'd need to test long and hard before getting a good result. I'd advise you find the author and ask for the source. It's faster this way.. I've stripped the freaking backdoor (was sending votes to some dude's msn back-links) and killed the limited amount of run periods. Other than that, you can't do more. EXECryptor is just for show, to see how many will attempt to go at it ;) ![]() |
|
Создано: 07 января 2008 14:52 · Личное сообщение · #5 ah thx sunbeam for replying. I don't think that bOYd would release his source for 10.4. and what do you mean with characteristics of a threat, Signature, Call API, Checksum, PE Header? the things i wanted to try was to cut off some stuff, crypt or pack with something different the way like you try to hide something for an AV. But i still think that even this won't work because after starting the bot you got 2 threads one with all your patches and and second one with the "original" file. maybe you got some other tips what i can try to do with it (beside asking for the source) to get it undetected. thx wali ps: are you going to continue your DBP tut? ![]() |
|
Создано: 07 января 2008 15:39 · Личное сообщение · #6 I need some files to continue the tutorial. Such as a valid license ![]() ![]() ![]() |
|
Создано: 07 января 2008 16:42 · Личное сообщение · #7 |
|
Создано: 07 января 2008 16:45 · Личное сообщение · #8 |
|
Создано: 07 января 2008 23:26 · Личное сообщение · #9 Find it posted anywhere, strip Armadillo off it, patch a JE right at the beginning (near OEP) and you will have a "clean" one ![]() ![]() ![]() |
|
Создано: 08 января 2008 00:31 · Личное сообщение · #10 SunBeam writes: Find it posted anywhere, strip Armadillo off it, patch a JE right at the beginning (near OEP) and you will have a "clean" one It was posted in other spots where people complained it worked for only 2 or 3 runs. The Delphi layer serves as a server emulator. hmpf sry can't follow this for aimboyd or DBP? SunBeam writes: I've unpacked DBP, but that doesn't mean it's cracked and runs I know :P ![]() |
|
Создано: 13 января 2008 18:05 · Личное сообщение · #11 |
|
Создано: 13 января 2008 20:20 · Поправил: kioresk · Личное сообщение · #12 |
|
Создано: 14 января 2008 01:23 · Личное сообщение · #13 |
![]() |
eXeL@B —› WorldWide —› Unpacking help (Execryptor) |