/binja-emotet

Primary LanguagePythonMIT LicenseMIT

Emotet API+string deobfuscator (v0.1)

Author: Francesco Muroni

Deobufscate API calls and strings in unpacked Emotet samples.

Description:

Helper plugin for the analysis of unpacked Emotet samples. Locate dynamically imported API functions and add tags to make them easily searchable.

Replace obfuscated strings with their original value.

License

This plugin is released under a MIT license.

Metadata Version

2