April 22Apr 22 VIP comment_12397 🔹 Program Name & Version:Program.exe🔹 VirusTotal:https://www.virustotal.com/gui/file/a4749906d8fac64b1dfc357c089b2d5b49659082df6f5a6ec2538e259c3b396f?nocache=1🔹 Protection Analysis (DIE, PEiD, ProtectionID results):DIE v3.10:File type: PE64Architecture: AMD64Endianness: Little EndianMode: 64-bitLinker: Microsoft LinkerLanguage: MSIL / C# (.NET)Framework: .NET Framework v4.8 (CLR v4.0.30319)Protector:.NET Reactor 6.xControl Flow ObfuscationAnti-TamperAnti-ILDASMHeuristic protection:Obfuscation (modified EP + CLR constructor + virtualization)Calls encryptionAnti-ILDASM techniquesAnti-analysis / Anti-debugPacked or compressed dataHigh entropy detectedCompressed resource section (.rsrc)Licensing:LicensingProvider attributeLicense manager detected🔹 Any Extra Protections (e.g. disk wiper, BSOD, VM detection):No destructive behavior detected.No disk wiper or BSOD behavior observed.Strong obfuscation and anti-tamper protections present.Possible anti-debug and anti-analysis mechanisms.VM detection: Not confirmed (static analysis only).🔹 What Does the Program Do?:Unknown exact functionality.The application is a .NET GUI program and appears to be protected with heavy obfuscation using .NET Reactor.Further dynamic analysis is required to determine its real behavior.🔹 Supported Systems & Architectures:Windows x64Compatible with .NET Framework 4.8 environments🔹 Screenshot(s) of the Program:🔹 Limitations:Heavily protected with .NET Reactor, making analysis and modification difficult.Requires unpacking and deobfuscation for deeper inspection.🔹 Download Link:https://www.mediafire.com/file/4ouyh7he0urxogk/Program.rar/file🔹 Additional Notes:Uses strong .NET obfuscation (control flow + virtualization).Contains anti-tamper and anti-decompilation protections.Resources appear compressed and possibly embedded.Recommended tools: dnSpyEx, x64dbg, ExtremeDumper, de4dot (custom builds).Difficulty: Medium 🚧 Link to comment https://decodehub.org/topic/1080-net-reactor-6x/ Share on other sites Share on Facebook {lang="reddit_text" Share on LinkedIn Share on Pinterest Share on X More sharing options... Share this post
May 4May 4 Founder comment_12832 I think I know someone who might be able to handle this, decrypt the file, and run it offline.@Fr0Mu PROFESSIONAL Link to comment https://decodehub.org/topic/1080-net-reactor-6x/#findComment-12832 Share on other sites Share on Facebook {lang="reddit_text" Share on LinkedIn Share on Pinterest Share on X More sharing options... Share this post
May 4May 4 Author VIP comment_12837 Update link: https://www.mediafire.com/file/ozfu8aurs2mo5n0/update.zip/file Link to comment https://decodehub.org/topic/1080-net-reactor-6x/#findComment-12837 Share on other sites Share on Facebook {lang="reddit_text" Share on LinkedIn Share on Pinterest Share on X More sharing options... Share this post
May 4May 4 comment_12842 it looks like some kind of a software you want to make people unpack and get the source code but definitely not a "CrackMe" Link to comment https://decodehub.org/topic/1080-net-reactor-6x/#findComment-12842 Share on other sites Share on Facebook {lang="reddit_text" Share on LinkedIn Share on Pinterest Share on X More sharing options... Share this post
May 4May 4 Founder comment_12844 45 minutes ago, Fr0Mu said:it looks like some kind of a software you want to make people unpack and get the source code but definitely not a "CrackMe"The file has been decrypted, but an online authentication check is required; the program won't open while the authentication check is active. PROFESSIONAL Link to comment https://decodehub.org/topic/1080-net-reactor-6x/#findComment-12844 Share on other sites Share on Facebook {lang="reddit_text" Share on LinkedIn Share on Pinterest Share on X More sharing options... Share this post
Create an account or sign in to comment