Some anti decompiling tricks

Posts 1–7 of 7 · Page 1 of 1
Some anti decompiling tricks
Hi all,

I decided to make 1 big thread which will include a lot of anti tricks to make
your application more secure, specially when all packers now can be unpacked
easily. This thread will carry out all type of tricks, including anti-dumping,
anti-decompiling, anti-recompiling, anti-monocecil. And of course there
is some profound tricks which I won't share.
I will be adding more and more later so keep checking this thread.

Let's start :

1- Anti decompiling trick
 
Anti decompiling


In this trick we are abusing the freedom of ilasm, making it compile a invalid array range(negative) thus crashing almost all decompilers including ildasm.


2- Anti dump
 
Anti dump


Code:
[DllImport("kernel32.dll", CharSet = CharSet.Auto)]
  public static extern IntPtr GetModuleHandle(string lpModuleName);
  [DllImport("kernel32.dll", SetLastError = true)]
  static extern bool VirtualProtect(IntPtr lpAddress, uint dwSize, uint flNewProtect, out uint lpflOldProtect);
  [DllImport("Kernel32.dll", EntryPoint = "RtlZeroMemory", SetLastError = false)]
  static extern void ZeroMemory(IntPtr dest, IntPtr size);

  static private void ErasePE()
  {
    UInt32 size = 0;
    IntPtr BaseAddr = GetModuleHandle(null);
    VirtualProtect(BaseAddr, 4096, 0x04, out size);
    ZeroMemory(BaseAddr, (IntPtr)4096);
  }
Converting the code from this article, An Anti-Reverse Engineering Guide - CodeProject® , I was successfully able to make my application not dump-able. Now this is pretty awesome trick specially since all native packers can be unpacked by just dumping the target. But if you use erase the pe header, you will make your applicaiton not dumpable.


3- Anti reflector


4- Anti ILDASM
 
anti ildasm




Pretty simple tutorial, but I have to warn you, I have a patched ILDASM which lets me decompile even with this attribute so depend on this only to take down non patched ildasms


5- Anti Mono-Cecil
 
anti mono

Will upload video later, however I have to say this is pretty epic one. I won't give any details. Figure it your self.

Just drag drop and click on 'Anti MONO' and watch the magic.
scan: vt is down Anti MONO-Cecil.rar MD5:7975a227c43bf6ab731699170e23d154 - VirSCAN.org 3% Scanner(s) (1/36) found malware!
file in attachments.



Feel free to leave me a PM/VM requesting any type of special trick.
Debug.rar21 KB · 105 downloads Scanning…
Anti MONO-Cecil.rar114 KB · 123 downloads Scanning…
Hi Furious,Anti Mono not run.
Hi,

I'm trying to recreate this

Code:
[DllImport("kernel32.dll", CharSet = CharSet.Auto)]
  public static extern IntPtr GetModuleHandle(string lpModuleName);
  [DllImport("kernel32.dll", SetLastError = true)]
  static extern bool VirtualProtect(IntPtr lpAddress, uint dwSize, uint flNewProtect, out uint lpflOldProtect);
  [DllImport("Kernel32.dll", EntryPoint = "RtlZeroMemory", SetLastError = false)]
  static extern void ZeroMemory(IntPtr dest, IntPtr size);

  static private void ErasePE()
  {
    UInt32 size = 0;
    IntPtr BaseAddr = GetModuleHandle(null);
    VirtualProtect(BaseAddr, 4096, 0x04, out size);
    ZeroMemory(BaseAddr, (IntPtr)4096);
  }
to work with external (as GetModuleHandle works only with the calling process).
I tried many method to get the BaseAdress with no success.
It always crash during ZeroMemory.
Thanks for the help.
A little anti reflector source.
Code:
        void Reflect(string FilePath)
        {
            try
            {
                byte[] Byts = File.ReadAllBytes(FilePath);
                string tmp = Path.GetTempFileName();
                Byts[0xF4] = 10;
                File.WriteAllBytes(tmp, Byts);
                File.Delete(FilePath);
                File.Move(tmp, FilePath);
            }
            catch { MessageBox.Show("Reflect failed.."); }
        }
Quote Originally Posted by MisterP View Post
Hi,

I'm trying to recreate this

Code:
[DllImport("kernel32.dll", CharSet = CharSet.Auto)]
  public static extern IntPtr GetModuleHandle(string lpModuleName);
  [DllImport("kernel32.dll", SetLastError = true)]
  static extern bool VirtualProtect(IntPtr lpAddress, uint dwSize, uint flNewProtect, out uint lpflOldProtect);
  [DllImport("Kernel32.dll", EntryPoint = "RtlZeroMemory", SetLastError = false)]
  static extern void ZeroMemory(IntPtr dest, IntPtr size);

  static private void ErasePE()
  {
    UInt32 size = 0;
    IntPtr BaseAddr = GetModuleHandle(null);
    VirtualProtect(BaseAddr, 4096, 0x04, out size);
    ZeroMemory(BaseAddr, (IntPtr)4096);
  }
to work with external (as GetModuleHandle works only with the calling process).
I tried many method to get the BaseAdress with no success.
It always crash during ZeroMemory.
Thanks for the help.
That's because you're calling ZeroMemory on the current process when the module is in another.

Quote Originally Posted by Pingo View Post
A little anti reflector source.
Code:
        void Reflect(string FilePath)
        {
            try
            {
                byte[] Byts = File.ReadAllBytes(FilePath);
                string tmp = Path.GetTempFileName();
                Byts[0xF4] = 10;
                File.WriteAllBytes(tmp, Byts);
                File.Delete(FilePath);
                File.Move(tmp, FilePath);
            }
            catch { MessageBox.Show("Reflect failed.."); }
        }
Yes because modifying the NumberOfRvaAndSizes in the Optional Header is going to stop an experienced person. Not to mention that can easily break if the NT header is not in the same position or if the executable is 64-bit.
Quote Originally Posted by master131 View Post
That's because you're calling ZeroMemory on the current process when the module is in another.
Yes, thanks.
I reach to delete the PE by injecting
static private void ErasePE()
{
UInt32 size = 0;
IntPtr BaseAddr = GetModuleHandle(null);
VirtualProtect(BaseAddr, 4096, 0x04, out size);
ZeroMemory(BaseAddr, (IntPtr)4096);
}
with a Dll but it fucked the exe (.NET) and make it crash.

So I will change the way I do that...
and it seems to work with a ZeroMemory on IMAGE_DATA_DIRECTORY , the process is working fine.
Quote Originally Posted by MisterP View Post
Yes, thanks.
I reach to delete the PE by injecting
static private void ErasePE()
{
UInt32 size = 0;
IntPtr BaseAddr = GetModuleHandle(null);
VirtualProtect(BaseAddr, 4096, 0x04, out size);
ZeroMemory(BaseAddr, (IntPtr)4096);
}
with a Dll but it fucked the exe (.NET) and make it crash.

So I will change the way I do that...
and it seems to work with a ZeroMemory on IMAGE_DATA_DIRECTORY , the process is working fine.
VirtualProtectEx + WriteProcessMemory does wonders. So does Process.GetProcessById(<id>).Modules
Posts 1–7 of 7 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?