Skip to content

ScyllaHide doenst work on VMProtect v2 #131

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Succubussix opened this issue Oct 15, 2021 · 8 comments
Open

ScyllaHide doenst work on VMProtect v2 #131

Succubussix opened this issue Oct 15, 2021 · 8 comments

Comments

@Succubussix
Copy link

Succubussix commented Oct 15, 2021

here's the sample https://disk.yandex.com/d/Dqk1qhxj6YV6cQ
both are packed with a different version of vmprotect .. v3 and v2..

ScyllaHide works fine with v3 but not on v2.

Not Working: bypassing anti-debug

pass: test

@lupier
Copy link

lupier commented Dec 3, 2021

file under password? are you serious?

@Mattiwatti
Copy link
Member

The password on the archive is test.

@lupier
Copy link

lupier commented Dec 3, 2021

No single detection. Try "break on system breakpoint"

@EricPlayZ
Copy link

EricPlayZ commented May 1, 2023

Bump, I have the same issue here. Using the VMProtect preset, debugging an x86 executable packed with VMProtect 2, i get to the entry point, I try to attach ScyllaHide to the process and the process immediately crashes after injection... Never had this issue on VMProtect 3 though.

@yashikada
Copy link

same here, I used SharpOD 0.6e and I solved my issue. Sure SharpOD is not very good is closed source and the dll is protected with vmprotect 2, but this issue is ignored for too many years.

@mrexodia
Copy link
Member

Yeah not really a lot of incentives to help people bypass vmprotect to make money for their own ends 😂

@yashikada
Copy link

@mrexodia money? Is protecting yourself from malware wrong?

@mrexodia
Copy link
Member

Not at all! It's just that people's motives for debugging VMProtected binaries are usually not related to malware 😅 Generally speaking ScyllaHide has been defeated by the direct syscalls, so it's kind of pointless to keep maintaining it. TitanHide used to work somewhat better, but generally speaking you'll want to invest in some unpacking technology to sidestep debuggers completely when dealing with malware.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants