3 ms·
It already is quite difficult to recover to this level, even for a relatively small malware codebase this probably took hundreds of man-hours to decompile into
by arsome 3y ago
It already is quite difficult to recover to this level, even for a relatively small malware codebase this probably took hundreds of man-hours to decompile into a meaningful state.
To protect it beyond a basic level - You can try but it's a cat-and-mouse game. A sufficiently skilled reverser will drop a debugger on your program, execute the code until it's past any decryption and then dump it from memory. So better schemes to obfuscate applications have been developed, like VMProtect, which makes a simple virtual machine with a custom instruction set and uses it to obfuscate your application. It's of course possible to break that as well, but it takes more time and requires more skill.