Some anti decompiling tricks
I decided to make 1 big thread which will include a lot of anti tricks to make
your application more secure, specially when all packers now can be unpacked
easily. This thread will carry out all type of tricks, including anti-dumping,
anti-decompiling, anti-recompiling, anti-monocecil. And of course there
is some profound tricks which I won't share.
I will be adding more and more later so keep checking this thread.
Let's start :
1- Anti decompiling trick
Anti decompiling
In this trick we are abusing the freedom of ilasm, making it compile a invalid array range(negative) thus crashing almost all decompilers including ildasm.
2- Anti dump
Anti dump
Code:
[DllImport("kernel32.dll", CharSet = CharSet.Auto)]
public static extern IntPtr GetModuleHandle(string lpModuleName);
[DllImport("kernel32.dll", SetLastError = true)]
static extern bool VirtualProtect(IntPtr lpAddress, uint dwSize, uint flNewProtect, out uint lpflOldProtect);
[DllImport("Kernel32.dll", EntryPoint = "RtlZeroMemory", SetLastError = false)]
static extern void ZeroMemory(IntPtr dest, IntPtr size);
static private void ErasePE()
{
UInt32 size = 0;
IntPtr BaseAddr = GetModuleHandle(null);
VirtualProtect(BaseAddr, 4096, 0x04, out size);
ZeroMemory(BaseAddr, (IntPtr)4096);
}
3- Anti reflector
anti reflector
4- Anti ILDASM
anti ildasm
Pretty simple tutorial, but I have to warn you, I have a patched ILDASM which lets me decompile even with this attribute so depend on this only to take down non patched ildasms
5- Anti Mono-Cecil
anti mono
Will upload video later, however I have to say this is pretty epic one. I won't give any details. Figure it your self.

Just drag drop and click on 'Anti MONO' and watch the magic.
scan: vt is down Anti MONO-Cecil.rar MD5:7975a227c43bf6ab731699170e23d154 - VirSCAN.org 3% Scanner(s) (1/36) found malware!
file in attachments.
Feel free to leave me a PM/VM requesting any type of special trick.


