Repository for code I've written to decrypt/decode malware configurations or assist me during malware analysis and reverse-engineering binaries
Here's a list of decryptors/decoders I've written (categorized by the name of the APT/TA):
- Sidewinder
- Decrypt encrypted .TMP payload dropped to disk
- Decode .JS file dropped to disk
Here's a list of helpers I've written to assist my malware analysis process:
- convertHextoBin
- Convert hex-encoded payload to Binary