Reverse Engineering RET Homepage RET Members Reverse Engineering Projects Reverse Engineering Papers Reversing Challenges Reverser Tools RET Re-Search Engine Reverse Engineering Forum Reverse Engineering Links

Go Back   Reverse Engineering Team Board > Reverse Engineering Board > .NET Reverse Engineering
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Thread Tools Display Modes
Old 04-09-2009, 05:08 AM
rongchaua rongchaua is offline
Senior Member
Join Date: Apr 2007
Posts: 91
Default .Net Id

When I reversed a .net assembly which is packed and obfuscated, I always confuse myself to define which of packer is being used to protect that assembly. So I would like to have a tool like PEiD to identify the signature of an assembly. I waited for a long time so that someone will write such tool but it seems that no one has time to do that. So yesterday I decided to write myself a small tool to identify the signature of assembly (not exact signature but the pattern which helps to identify the packer or obfuscator). It was written only for .net (not native code). I will try support to identify more signatures.

This tool is now on beta version. Use it on your risk, you can help me to improve it by sending a muster assembly with a comment telling me which packer or obfuscator is applied on that assembly.

* Requirements : .NET Framework 2.0

* Version:
* Supported version of Assembly
o All versions
* All comments for this tool. Post directly below.

NOTE: If this tool doesn't work with your system, post here your errors.


* [] : Beta Version
My site:
Reply With Quote
Old 04-10-2009, 04:44 AM
Dielbach Dielbach is offline
Join Date: Sep 2008
Posts: 6

Thank you, something I am looking for a long time.
Reply With Quote
Old 04-10-2009, 08:21 AM
tankaiha tankaiha is offline
Join Date: May 2007
Posts: 30

cool, I want this for long time!
two advice: drag and drop detection of more proections(IntelliLock,Goliath,Themida,etc)
Reply With Quote
Old 04-14-2009, 03:42 AM
sirp sirp is offline
Senior Member
Join Date: Apr 2008
Posts: 76
Default nice

yep realy usefull ,until now i used the sigs Kurapica gave me for cff explorer ... lets see if the proggy is more exact ,) thx
Reply With Quote

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2023, Jelsoft Enterprises Ltd.