吾爱破解 - LCG - LSG |安卓破解|病毒分析|www.52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 4857|回复: 6
收起左侧

[Other] Armadillo Informant 0.9 (Beta) Static Armadillo Scanner

[复制链接]
Hmily 发表于 2011-3-25 11:52
Hi to all,

After a long and fruitful investigation of The Armadillo Protection System internals I am able to show to you the some of the results of my research. I am presenting a public beta version of AI 0.9b (Armadillo Informant), which at present has been tested on files protected with Armadillo from version 4.40 up to current 8.20 only.

Note:

* All operations are performed on static files, this tool doesn't execute any processes.
* Versions lower than 3.75 are not supported currently, please note this.
* Feature requests and bug reports can be posted in the original thread at ARTeaam and i'll answer them as soon as i can.
* When completed, the tool will be accompanied by a full tutorial explaining how the tool works with Armadillo protected files.


So far it retrieves:

* Version of Armadillo.
* Compression level.
* Protection options.
* Whether or not Armadillo has substituted DWORDs in the .pdata section to thwart static unpacking of the content (v6.xx+)

**************************
*** Currently Disabled ***
**************************
* Other Options (Disable REGISTER, etc) - this function is partially incomplete until i map out all the bits.
* Name of .ARM project the file belongs to.
**************************

There are further additions planned, i'll post them as they are implemented and ready for testing.





File:                   Armadillo.exe
Path:                   C:\Program Files\SoftwarePassport
SR signature:           Yes
Detected version:       8.20

* Compression Option *

Compression level:      Best/Slowest

* Protection Options *

CopyMem-II & Debug Blocker
Enable Import Table Elimination
Enable Nanomite Processing
Enable Random PE Names

Dword shuffling used:   Yes
Number of dwords:       250

~ Other Options ~
None found

ARM Project name:       ArmadilloV8
File:                   Armadillo.exe
Path:                   C:\Documents and Settings\Ghandi\Desktop
SR signature:           Yes
Detected version:       7.40

* Compression Option *

Compression level:      Best/Slowest

* Protection Options *

CopyMem-II & Debug Blocker
Enable Import Table Elimination
Enable Nanomite Processing
Enable Random PE Names

Dword shuffling used:   Yes
Number of dwords:       148

~ Other Options ~
None found

ARM Project name:       ArmadilloV7


File:                   Armadillo.exe
Path:                   F:\
SR signature:           Yes
Detected version:       6.24

* Compression Option *

Compression level:      Best/Slowest

* Protection Options *

CopyMem-II & Debug Blocker
Enable Import Table Elimination
Enable Nanomite Processing
Enable Random PE Names

Dword shuffling used:   No

~ Other Options ~
None found

ARM Project name:       ArmadilloV6



File:                   Armadillo.exe
Path:                   F:\
SR signature:           Yes
Detected version:       4.40

* Compression Option *

Compression level:      Best/Slowest

* Protection Options *

CopyMem-II & Debug Blocker
Enable Import Table Elimination
Enable Nanomite Processing

Dword shuffling used:   No

~ Other Options ~
None found

ARM Project name:       ArmadilloV3



File:                   CrazyPC.exe
Path:                   F:\Program Files\Digital Chocolate\Crazy Penguin Catapult
SR signature:           Yes
Detected version:       5.40

* Compression Option *

Compression level:      Best/Slowest

* Protection Options *

Standard Protection & Debug Blocker

Dword shuffling used:   No

~ Other Options ~
Use Hardware Locking

ARM Project name:       Double Trump Package 321171e0-69ec-4a57-b1f6-0c293169e0b8
File:                   DTChannel.dll
Path:                   F:\Program Files\Digital Chocolate\Crazy Penguin Catapult
SR signature:           Yes
Detected version:       5.40

* Compression Option *

Compression level:      Best/Slowest

* Protection Options *

Standard Protection Only

Dword shuffling used:   No

~ Other Options ~
Use Hardware Locking

ARM Project name:       Double Trump Channel 5c27fc5f-9a21-4434-b4f9-bab79f534008





Original Thread:
http://www.accessroot.com/arteam/forums/index.php?showtopic=10518

HR,
Ghandi




AI 0.9.4b.rar (69.58 KB, 下载次数: 8)

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

头像被屏蔽
11111 发表于 2011-3-25 12:09
提示: 作者被禁止或删除 内容自动屏蔽
 楼主| Hmily 发表于 2011-3-25 12:23
回复 11111 的帖子

用来检测穿山甲加壳版本和加密选项等信息,类似Armadillo find protected.
WanderMax 发表于 2011-3-25 12:37
gry8686 发表于 2011-3-25 12:44
支持楼主的分享
Alar30 发表于 2011-3-25 17:08
谢谢了哈。。。
zss5312 发表于 2011-3-25 23:42
我还以为是壳、
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则 警告:本版块禁止灌水或回复与主题无关内容,违者重罚!

快速回复 收藏帖子 返回列表 搜索

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-5-15 05:28

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表