Skip to content
View in the app

A better way to browse. Learn more.

DecodeHub - Reverse Engineering, Crackmes, Software & Coding

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

.NET Reactor 6.x

Featured Replies

  • VIP

🔹 Program Name & Version:
Program.exe

🔹 VirusTotal:
https://www.virustotal.com/gui/file/a4749906d8fac64b1dfc357c089b2d5b49659082df6f5a6ec2538e259c3b396f?nocache=1

🔹 Protection Analysis (DIE, PEiD, ProtectionID results):
DIE v3.10:

  • File type: PE64

  • Architecture: AMD64

  • Endianness: Little Endian

  • Mode: 64-bit

  • Linker: Microsoft Linker

  • Language: MSIL / C# (.NET)

  • Framework: .NET Framework v4.8 (CLR v4.0.30319)

  • Protector:

    • .NET Reactor 6.x

    • Control Flow Obfuscation

    • Anti-Tamper

    • Anti-ILDASM

  • Heuristic protection:

    • Obfuscation (modified EP + CLR constructor + virtualization)

    • Calls encryption

    • Anti-ILDASM techniques

    • Anti-analysis / Anti-debug

    • Packed or compressed data

    • High entropy detected

    • Compressed resource section (.rsrc)

  • Licensing:

    • LicensingProvider attribute

    • License manager detected

🔹 Any Extra Protections (e.g. disk wiper, BSOD, VM detection):
No destructive behavior detected.
No disk wiper or BSOD behavior observed.
Strong obfuscation and anti-tamper protections present.
Possible anti-debug and anti-analysis mechanisms.
VM detection: Not confirmed (static analysis only).

🔹 What Does the Program Do?:
Unknown exact functionality.
The application is a .NET GUI program and appears to be protected with heavy obfuscation using .NET Reactor.
Further dynamic analysis is required to determine its real behavior.

🔹 Supported Systems & Architectures:
Windows x64
Compatible with .NET Framework 4.8 environments

🔹 Screenshot(s) of the Program:
image.png

🔹 Limitations:
Heavily protected with .NET Reactor, making analysis and modification difficult.
Requires unpacking and deobfuscation for deeper inspection.

🔹 Download Link:
https://www.mediafire.com/file/4ouyh7he0urxogk/Program.rar/file

🔹 Additional Notes:

  • Uses strong .NET obfuscation (control flow + virtualization).

  • Contains anti-tamper and anti-decompilation protections.

  • Resources appear compressed and possibly embedded.

  • Recommended tools: dnSpyEx, x64dbg, ExtremeDumper, de4dot (custom builds).

  • Difficulty: Medium 🚧

  • 2 weeks later...
  • Replies 9
  • Views 492
  • Created
  • Last Reply

Top Posters In This Topic

Most Popular Posts

  • cambaz
    cambaz

    I think I know someone who might be able to handle this, decrypt the file, and run it offline. @Fr0Mu

Posted Images

  • Founder

I think I know someone who might be able to handle this, decrypt the file, and run it offline.

@Fr0Mu

PROFESSIONAL

it looks like some kind of a software you want to make people unpack and get the source code but definitely not a "CrackMe"

  • Founder
45 minutes ago, Fr0Mu said:

it looks like some kind of a software you want to make people unpack and get the source code but definitely not a "CrackMe"

The file has been decrypted, but an online authentication check is required; the program won't open while the authentication check is active.

PROFESSIONAL

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Important Information

Terms of Use

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.