تقييم الموضوع :
  • 8 أصوات - بمعدل 3.38
  • 1
  • 2
  • 3
  • 4
  • 5
SharpOD x64 (A_AntiDebug Plugin. Support for x64dbg)
#1
.Now more and more 64-bit system, ollydbg is a very useful debugger, but in 64-bit system, can not find support ollydbg hidden plugin, so I coded Sharpod plugin
.Use with the Strong plugin. Other hidden plugins may cause conflicts, such as: PhantmOm ScyllaHide
Novice recommended configuration
 
[صورة مرفقة: FB1Kkwy.jpg][صورة مرفقة: W3hZGwa.jpg]
 
  • Hide Peb64
  • Change Caption (random all (window & sub windows & menu) caption)
  • Hide Process
  • Fake ParentProcess
  • Show CrashInfo
  • Hook *ZwFunctions (This function mainly reference to Strong Plugin driver source)
  • Remove DebugPrivileges
  • VMP3.1(above) (VMP3.1 or later uses the syscall privilege command to query ProcessDebugFlags )
  • Protect Drx

Driver
  • Hook SSDT (invalid)
  • Hook ShadowSSDT(invalid)
  • restore DebugObject ValidAccessMask
  • Bypass ObjectHook(Process&Thread)
 
I tested the following protection ,working my WIN7 and WIN10 64-bit system
  • Safengine NetLicenseor v2.3.9.0
  • WinLicense_x32_x64_v2.3.9.0
  • Themida_x32_x64_v2.4.6.0
  • VMProtect 2.x - 3.1.2
  • VProtect Pro 2.1
  • Obsidium v1.5.2
  • ZProtect v1.6
  • Yoda's Protect v1.03
http://s2.dosya.tc/server8/cv9m5a/SharpOD_x64_v0.6b-password_123_.rar.html
أعضاء أعجبوا بهذه المشاركة : mrbox007 , samoray , Sangavi , adhem , zeta_hanan , kesmezar , rce3033 , 0b3l1sk , toromax , th3m4tr!x


الردود في هذا الموضوع
SharpOD x64 (A_AntiDebug Plugin. Support for x64dbg) - بواسطة vosiyons - 09-05-2019, 09:05 AM

التنقل السريع :


يقوم بقرائة الموضوع: بالاضافة الى ( 5 ) ضيف كريم