Skip to content

julupu/oski_string_decrypt

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 

Repository files navigation

oski_string_decrypt

rzpipe script to decrypt strings from Oski Stealer. Currently contains hardcoded addresses.

Blogpost: https://julian-wolf.eu/2022/06/17/oski-stealer-unpacking-and-string-decryption/

Script can be run standalone from commandline or in the context of rizin/cutter.

Standalone

.\oski_string_decrypt.py file.exe

Rizin

rizin.exe file.exe
. oski_string_decrypt.py

The comments are added at every function call for the decryption function:

image

Cutter

Similar to Rizin, you open the console and run the script

image

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages