Exetools

Exetools (https://forum.exetools.com/index.php)
-   Community Tools (https://forum.exetools.com/forumdisplay.php?f=47)
-   -   .NET Obfuscator Detector (https://forum.exetools.com/showthread.php?t=15751)

LordCoder 04-27-2014 03:32

.NET Obfuscator Detector
 
Hello,

After a bit period of inactivity I come here with a new project.

As you know, DNiD is not updated. ProtectioniD has a bit of detection for .NET but not all the obfuscators. So I decided to create a new obfuscator detector (and because I don't know how to name my projects I just put that :D).

Features:

-Good detection with +85% probability. It doesn't show a result if it's not sure.
-Gives clear information about which is/are the protector/s.
-It even gives information if it's a trial version and how many days are left.
-Drag and drop is enabled.
-Quickly access and check the obfuscator!

Currenctly it detects +20 obfuscators/packers/protectors.

Download it here: https://www.firedrive.com/file/D7D13E361752F551

serseri_1453 04-27-2014 17:23

Thanks for the Program

Confuser know yet realase of walls does not recognize the
Net Reactor 3-4 does not recognize the version of

Multi-scan feature list in the form indicates that it is much better

ontryit 04-28-2014 15:43

Quote:

Originally Posted by LordCoder (Post 91083)
Hello,

After a bit period of inactivity I come here with a new project.

As you know, DNiD is not updated. ProtectioniD has a bit of detection for .NET but not all the obfuscators. So I decided to create a new obfuscator detector (and because I don't know how to name my projects I just put that :D).

Features:

-Good detection with +85% probability. It doesn't show a result if it's not sure.
-Gives clear information about which is/are the protector/s.
-It even gives information if it's a trial version and how many days are left.
-Drag and drop is enabled.
-Quickly access and check the obfuscator!

Currenctly it detects +20 obfuscators/packers/protectors.

Download it here: https://www.firedrive.com/file/D7D13E361752F551

I think just simple name it "LordCoder Obfuscator Detector", its unique and good enogh :)

LordCoder 05-01-2014 20:17

New version! I hope you like it :D. It's now stable and added more obfuscators:
Quote:

-Added njRAT:
-Gives information about hacker's IP, fake process and njRAT's version.
-Added DotNet Reactor
-Added context menu for Explorer
-Added "Check for updates" function
-Improved & fixed detection on ILProtector
-Fixed CryptoObfuscator detection
Download it here: https://www.firedrive.com/file/E468DCBBBAFB396C

Any bug found? Please report!

LordCoder 05-01-2014 21:40

Here the link: https://www.firedrive.com/file/38831938053F98FC
I removed the other one.

lihanbok 05-02-2014 01:56

This is good tools. I will try it! Thank you so much!
Brs,'
li

riverstore 05-02-2014 15:43

It's a good tool. Do you support Confuser? The tool can't detect a program packed by Confuser

leetone 05-02-2014 18:35

Quote:

Originally Posted by LordCoder (Post 91164)
Here the link: https://www.firedrive.com/file/38831938053F98FC
I removed the other one.

Much appreciated. I am so glad to have an updated obfuscation checker.

ontryit 05-02-2014 21:05

Quote:

Originally Posted by LordCoder (Post 91160)
New version! I hope you like it :D. It's now stable and added more obfuscators:


Download it here: https://www.firedrive.com/file/E468DCBBBAFB396C

Any bug found? Please report!

Little suggesstion for the GUI, especially the Report Memo, you should add 'Clear Report' on the right context menu or automatically clear the previous report when load a new .NET Assemblies.

Why there no -> [Language: ... ] item report like the screenshot you put on tuts4you?

Thank you

LordCoder 05-04-2014 03:26

Quote:

Originally Posted by riverstore (Post 91171)
It's a good tool. Do you support Confuser? The tool can't detect a program packed by Confuser

Oh forgot to add the packer option. Thanks for the report!

Quote:

Originally Posted by ontryit (Post 91178)
Little suggesstion for the GUI, especially the Report Memo, you should add 'Clear Report' on the right context menu or automatically clear the previous report when load a new .NET Assemblies.

Why there no -> [Language: ... ] item report like the screenshot you put on tuts4you?

Thank you

Thanks for the feature. I will add it for the next version. :) That language menu was a demo I made. I will implement language options for the next release.

serseri_1453 05-04-2014 17:11

This topic packleri if we add, it's more comfortable for you, so that the individual they do not add in bulk, you will be added. In particular, this version attention if you will be more comfortable "smart assembly" , "net reactor" , "confuser", etc

http://forum.exetools.com/showthread.php?p=91204#post91204

Multi-while browsing, to log you can add a recording.

heima911 05-07-2014 10:27

.NET Obfuscator Detector
 
Quote:

Originally Posted by LordCoder (Post 91196)
Oh forgot to add the packer option. Thanks for the report!



Thanks for the feature. I will add it for the next version. :) That language menu was a demo I made. I will implement language options for the next release.


. NET Obfuscator Detector, you can give the latest version of downloading? Thank you

Alcatraz3222 05-14-2014 18:56

work really fine, thank you LordCoder, @riverstore for me also not detect confuser, i guess it is not added, anyway is a good detector for NET

0xd0000 05-18-2014 14:02

I was going to slip a bit of code into your app so I could integrate with the context menu, but realize your still in Beta and and likely adding tons of features.

I used to work the scene with author of DNID - I'm glad to see someone else pick up where he left off.

Request if you have time - Add File Arguments so it could be passed any file, rasher then dealing with drag and drop.

Something simple...

string[] args = Environment.GetCommandLineArgs();

Mahmoudnia 08-09-2014 06:09

Changes from 0.1 to 0.2
=======================
-Added xRAT
-Gives full info about it (like njRAT).
-Improved some detections.
-Some others I don't remember :P

http://www.firedrive.com/file/46116551681C3349

evlncrn8 08-09-2014 13:30

i'll be updating protection id shortly with new stuff, so i can incorporate this (with your permission if that ok), or you can send me info /' whatnot.. entirely up to you.. i've just been busy and havent had much time to do updates.. especially with cdkiller now gone for so long

edit - saw theres no external database.. and im not really in the mood atm to walk through .net stuff.. even if you paid me some bitcoins (im sure you'll get that reference) ;p

evlncrn8 08-09-2014 14:16

your method is to walk the net classes / definitions etc and do string matches that way yep? i had that in pid already, but never really expanded on it (partially because im not a super fan of .net)... i'll see what i can do with the next release

LordCoder 08-09-2014 15:49

Quote:

Originally Posted by evlncrn8 (Post 93387)
your method is to walk the net classes / definitions etc and do string matches that way yep? i had that in pid already, but never really expanded on it (partially because im not a super fan of .net)... i'll see what i can do with the next release

Yeah exactly. I sent you a PM :)

SubzEro 08-11-2014 02:09

1 Attachment(s)
DotNet Obfuscator Detector v0.3

Quote:

Improved CryptoObfuscator detection
- Added QLM, Desaware and NetSeal detection
- Minor bugs fixed

Mahmoudnia 08-11-2014 03:37

@ LordCoder

I have an error about outside the bounds of the array when I want to check my protected target. This error occur when scan result is -NO OBFUSCATOR DETECT- in Both of databases.

serseri_1453 09-24-2016 02:24

Link dead re upload plaese

bolo2002 09-24-2016 22:36

@serseri_1453:Still valid up the post of Mahmoudnia.

Spiderz_Soft 11-06-2016 08:32

Link is dead. please update it.

TechLord 11-06-2016 10:49

Quote:

Originally Posted by Spiderz_Soft (Post 107621)
Link is dead. please update it.

Bro Spiderz, the latest version attached to THIS post in this same thread :)

Spiderz_Soft 11-06-2016 15:41

Quote:

Originally Posted by SubzEro (Post 93432)
DotNet Obfuscator Detector v0.3

There is some issue in downloading. i already try this at night and now again.

Take a look @Techlord Bro:

PHP Code:

http://image.prntscr.com/image/9ac0347e2d2f41c0a0b83d46f19a1624.png 

After waiting few minutes file downloading failed. it should not take 1 seconds to download. its showing 41 Minutes. maybe its issue in website or just with this file. that's why i wrote last night link is dead! i hope so i am not only first who is getting this issue.. others members can try to download this file and see What will happened! Time will be Stuck for you maybe as its for me.

RDGMax 11-06-2016 21:53

https://www.sendspace.com/file/v0xokc

download alternative link


All times are GMT +8. The time now is 01:50.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2026, vBulletin Solutions, Inc.
Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX