Jump to content

How to decrypt an encrypted .dll file with GDB gcore (Root & ARM only)


ThePianoGuy

4 posts in this topic

Recommended Posts

Hi there,

 

 

 

 

I will show you how to decrypt and encrypted .dll file (when trying to MOD Unity based Android games) using Gcore dump and WinHex.

 

 

 

 

 

Before we start, how to check if a .dll file is encrypted?

 

 

 

 

 

Easy. When you open a .dll file into Reflector and you get:

 

 

 

 

 

"Assembly-CSharp (this could change, depending on the name of the file), File is not a portable executable. DOS header does not contain 'MZ' signature."

 

 

 

 

 

it means you have got an encrypted DLL!

 

 

 

 

 

See image:

 

 

 

 

 

Mt9bkqf.png

 

 

 

 

 

It means the DLL file does not have a valid MZ/PE header so you can't open/modify it. DLL files require MZ/PE headers in order to view its content and, to prevent hacking, some game developers protect their game erasing these MZ/PE headers from some dll files.

 

 

 

 

 

Now let's start with the requirements!

 

 

 

 

 

First of all, you need:

 

 

1. To have some Android Hacking experiences (otherwise you will not understand a single word of this Topic)

 

 

2. A rooted Android device

 

 

3. .NET Reflector or JustDecompile installed on your computer (if you've got hacking experience, you should already have this tool)

 

 

4. A computer running at least Windows XP

 

 

5. A Rooted Android device (Works with BlueStacks) running Android 4.2.2 and newer versions. Previous version might not work.

 

 

Works with Bluestacks. Custom roms with Android 4.2.2+ based are supported

 

 

6. At least 1 GB of RAM on your Device. A minimum of 300-400 MB free RAM space is required

 

 

7. Latest verison of SuperSU or other Superuser apps

 

 

8. BusyBox for Android. Get it from HERE

 

 

9. Terminal app for Android. You can download it from HERE

 

 

10. gcore installed on your device. Download it from: HERE

 

 

11. Any file explorer app installed on your Android device. I'd recommended X-plore

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

55NjVLk.jpg

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

PtsKJ2l.pngVWiprRv.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

oMPbxeI.jpg

 

 

 

 

 

 

 

 

 

 

 

 

VEKB0Zp.png

 

 

 

 

 

 

 

 

 

 

 

 

dH2dx7q.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

su

 

 

 

 

 

 

 

 

 

 

YwQuPVl.png

 

 

 

 

 

 

 

 

 

 

 

root@[member='YourName'] #

 

 

 

 

 

 

 

 

fIzHnqp.png

 

 

 

 

 

 

 

 

 

 

 

dumpsys meminfo

 

 

 

 

 

 

 

 

 

 

or

 

 

 

 

 

 

dumpsys meminfo | grep com.*

 

 

 

 

 

 

 

 

 

 

or

 

 

 

 

 

 

dumpsys meminfo | grep th.*

 

 

 

 

 

 

 

 

 

 

UynNHbb.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

118740 kB: com.nhnent.SKQUEST (pid 383 / activities)

 

 

 

 

 

2f4kK8y.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

gdb -pid xxxxx

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

BjM722D.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

(gdb)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

chmod 777 /system/bin/gdb && chmod 777 /system/bin/gdbserver

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

gcore /sdcard/anynames

 

 

 

 

 

 

 

 

 

 

evw3QCI.png

 

 

 

 

 

 

 

 

 

 

 

 

 

daIMwGJ.png

 

 

 

 

 

 

 

 

 

 

 

Saved corefile /sdcard/xxxxxxxx

 

 

 

 

 

1k2XoSb.png

 

 

 

 

 

 

 

 

 

 

 

 

qu0dUi6.jpg

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

21XDniJ.jpg

 

 

 

 

 

 

 

 

 

 

KyVpF3A.jpg

 

 

 

 

 

OR

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

1zZ2okI.pnglDxOJBM.png

 

 

 

 

 

 

 

 

 

 

BLAMO2F.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

vwiY6Sl.jpg

 

 

 

 

 

 

 

 

 

 

G1TXfOH.png

 

 

 

 

 

 

 

 

 

 

nABBcma.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

HfbJdcY.png

 

 

 

 

 

 

 

 

 

 

AR43Mxe.jpg

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

MsPP0tr.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

eDtKnU0.png

 

 

 

 

 

 

 

 

 

 

 

Assembly-CSharp.dll

Assembly-CSharp-firstpass.dll

Assembly-UnityScript.dll

Assembly-UnityScript-firstpass.dll

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

mZB1PnI.png

 

 

 

 

 

 

 

 

 

 

 

Assembly-CSharp.dll = 000034.dll

Assembly-CSharp-firstpass.dll = 000030.dll

Assembly-UnityScript.dll = 000028.dll

Assembly-UnityScript-firstpass.dll = 000013.dll

 

 

 

 

 

 

 

 

 

 

B0CD3jO.png

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

AndnixSH

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Updated by AndnixSH
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below. For more information, please read our Posting Guidelines.
Reply to this topic... Posting Guidelines

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Our picks

    • [ Dragon Ball Legends Japan ] ドラゴンボール レジェンズ  v5.5.1 - [ Enemies Don't Attack & More]
      Modded/Hacked App: ドラゴンボール レジェンズ By BANDAI NAMCO Entertainment Inc.
      Bundle ID: jp.co.bandainamcoent.BNEI0333
      iTunes Store Link: https://itunes.apple.com/jp/app/ドラゴンボール-レジェンズ/id1358232022?mt=8


      Mod Requirements:
      - Jailbroken or Non-Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.


      Hack Features:
      - Enemies Don't Attack
      - No Ki Cost
      - Unlimited Ki
      - No Character Swap CoolDown
      - No Vanish CoolDown
      - Auto Complete All Challenges - Currency/Chrono Crystals Hack! 
      - Always Critical
      - All Cards Give DragonBall 

       This hack only works on x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.
      • 2,941 replies
    • [ DBL ]ドラゴンボール レジェンズ v5.5.1 - [ Instant - Win & More ]
      Modded/Hacked App: ドラゴンボール レジェンズ By BANDAI NAMCO Entertainment Inc.
      Bundle ID: jp.co.bandainamcoent.BNEI0333
      iTunes Store Link: https://itunes.apple.com/jp/app/ドラゴンボール-レジェンズ/id1358232022


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate (from Cydia).
      - PreferenceLoader (from Cydia).


      Hack Features:
      - x Player Damage - x1 - 20 
      - x Player Defense - x1 - 20 
      - One Hit Kill
      - God Mode 
      - 1 Enemy Per Quest
      - Instant - Win - Enable It When You In Battle
      - No Swap CoolDown
      - No Vanish CoolDown
      - No KI Cost
      - Auto Complete All Challenges-> Currency/Chrono Crystals Hack!
      - Always Critical
      - Tutorial Bypass
      - All Cards Give DragonBalls

      All functions are unlinked and only for player, you!
      • 1,580 replies
    • Harry Potter: Hogwarts Mystery v5.9.6 - [ Unlimited Energy & More ]
      Modded/Hacked App: Harry Potter: Hogwarts Mystery By Jam City, Inc.
      Bundle ID: com.tinyco.potter
      iTunes Store Link: https://apps.apple.com/us/app/harry-potter-hogwarts-mystery/id1333256716


      Hack Features:
      - Unlimited Energy
      - Max Attributes Level
      - Free Shop - Energy & Some Pets 
      - Max Creature Mastery Level
      - Unlimited Gems - Do Task And You'll Gain Gems
      - Feeding Button Enabled
      • 434 replies
    • Harry Potter: Hogwarts Mystery v5.9.6 - [ Unlimited Energy & More ]
      Modded/Hacked App: Harry Potter: Hogwarts Mystery By Jam City, Inc.
      Bundle ID: com.tinyco.potter
      iTunes Store Link: https://apps.apple.com/us/app/harry-potter-hogwarts-mystery/id1333256716


      Hack Features:
      - Unlimited Energy
      - Max Attributes Level
      - Free Shop - Energy & Some Pets 
      - Max Creature Mastery Level
      - Unlimited Gems - Do Task And You'll Gain Gems
      - Feeding Button Enabled
      • 814 replies
    • Adorimon: Arena of Ancient v1.3.568 Cheats +4
      Modded/Hacked App: Adorimon: Arena of Ancient By Mai Duc
      Bundle ID: com.ubiplay.petfi.adorimon
      iTunes Store Link: https://apps.apple.com/us/app/adorimon-arena-of-ancient/id6443480229?uo=4

       

      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Unlimited currents
      - Vip lv 15
      - Unlimited point upgrade
      - Feed max
      • 70 replies
    • Adorimon: Arena of Ancient v1.3.568 Cheats +4
      Modded/Hacked App: Adorimon: Arena of Ancient By Mai Duc
      Bundle ID: com.ubiplay.petfi.adorimon
      iTunes Store Link: https://apps.apple.com/us/app/adorimon-arena-of-ancient/id6443480229?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Unlimited currents
      - Vip lv 15
      - Unlimited point upgrade
      - Feed max
      • 110 replies
    • Fashion Universe v1.9 Cheats +2
      Modded/Hacked App: Fashion Universe By Voodoo
      Bundle ID: com.hypnocatstudio.fashionuniverse
      iTunes Store Link: https://apps.apple.com/us/app/fashion-universe/id1597104322?uo=4


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Premium: Setting -> Vibration -> Float icon -> In-App Purchase -> VoodooPremium
      - Unlimited currency
      • 0 replies
    • Fashion Universe v1.9 Cheats +2
      Modded/Hacked App: Fashion Universe By Voodoo
      Bundle ID: com.hypnocatstudio.fashionuniverse
      iTunes Store Link: https://apps.apple.com/us/app/fashion-universe/id1597104322?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Premium: Setting -> Vibration -> Float icon -> In-App Purchase -> VoodooPremium
      - Unlimited currency
      • 0 replies
    • Sew 3D v2.4.8 Cheats +2
      Modded/Hacked App: Sew 3D By Voodoo
      Bundle ID: com.friendsgamesincubator.sewit
      iTunes Store Link: https://apps.apple.com/us/app/sew-3d/id1614461317?uo=4


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Premium: Setting -> Restore purchases -> Float icon -> In-App Purchase -> VoodooPremium
      - Unlock all skins
      • 0 replies
    • Sew 3D v2.4.8 Cheats +2
      Modded/Hacked App: Sew 3D By Voodoo
      Bundle ID: com.friendsgamesincubator.sewit
      iTunes Store Link: https://apps.apple.com/us/app/sew-3d/id1614461317?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Premium: Setting -> Restore purchases -> Float icon -> In-App Purchase -> VoodooPremium
      - Unlock all skins
      • 0 replies
    • Word Web! v5.7 Cheats +3
      Modded/Hacked App: Word Web! By Voodoo
      Bundle ID: com.Axis.WordWeb
      iTunes Store Link: https://apps.apple.com/us/app/word-web/id1618681059?uo=4

       

      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Premium: Setting -> Haptic ->Float Icon -> VoodooPremium
      - SR Debug: Setting -> Sound
      - Unlimited coin (spend) 
      • 0 replies
    • Word Web! v5.7 Cheats +3
      Modded/Hacked App: Word Web! By Voodoo
      Bundle ID: com.Axis.WordWeb
      iTunes Store Link: https://apps.apple.com/us/app/word-web/id1618681059?uo=4

       

      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Premium: Setting -> Haptic ->Float Icon -> VoodooPremium
      - SR Debug: Setting -> Sound
      - Unlimited coin (spend) 
      • 0 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines