Saturday, 22 October 2011

Howto: Deobfuscating malicious code.


This post is the summary from Pandalabs's blog. If you want to see full detail, please go to the source.



1. Install Malzilla

2. Copy the obfuscate code into Malzilla

3. Hit the "Format Code" button.

4. Copy the code into text editor

5. Get the Javascript part into the new page for easy analyses.

6. Find the first function that was run when script start.

7. Create the code that will

No comments:

Post a Comment