Skip to content

Latest commit

 

History

History
12 lines (7 loc) · 466 Bytes

README.md

File metadata and controls

12 lines (7 loc) · 466 Bytes

Unicorn String Deobfuscator

A Unicorn based emulator to deobfuscate Equation Group string XOR obfuscation used in many samples.

Instead of reversing the algo just ripped off the function and emulated it on Unicorn.

Just a simple demo on how to use Unicorn to easily emulate functions you don't want to reverse because you are too lazy or they are too annoying and you just want to execute them.

Requires Unicorn Engine (http://unicorn-engine.org).

Have fun, fG!