4 ms·
Hopefully this isn't too off topic, but could you explain how to even start approaching this from a RE/malware analysis perspective? I'm guessing there's no dr
by elago 9y ago
Hopefully this isn't too off topic, but could you explain how to even start approaching this from a RE/malware analysis perspective?
I'm guessing there's no drag-and-drop de-obfuscate tool like there is for some of the common .NET obfuscators.
Do you just rely on behavioral/dynamic methods?
- problems 9y agoFor even the nastiest of obfuscators there are often attempts at deobfuscators... https://github.com/kirschju/demovfuscator https://github.com/kirschju/demovfuscator
- shakna 9y agoI was just looking to replace a specific function call, because the company weren't using VC, and no longer had a working codebase. So I was hunting a particular pattern to replace, that I knew probably existed. A simple combination of demovfuscator, regex on the "original" asm and eyeballing it succeeded in the end.