https://github.com/gdbinit/evilquest_deobfuscator
EvilQuest/ThiefQuest malware strings decrypter/deobfuscator
https://github.com/gdbinit/evilquest_deobfuscator
Last synced: 10 months ago
JSON representation
EvilQuest/ThiefQuest malware strings decrypter/deobfuscator
- Host: GitHub
- URL: https://github.com/gdbinit/evilquest_deobfuscator
- Owner: gdbinit
- Created: 2020-09-18T12:16:20.000Z (over 5 years ago)
- Default Branch: master
- Last Pushed: 2020-09-18T17:35:22.000Z (over 5 years ago)
- Last Synced: 2025-04-13T05:29:19.116Z (about 1 year ago)
- Language: Go
- Size: 7.81 KB
- Stars: 7
- Watchers: 4
- Forks: 0
- Open Issues: 0
-
Metadata Files:
- Readme: README.md
Awesome Lists containing this project
- awesome-csirt - evilquest_deobfuscator
README
Latest EvilQuest/ThiefQuest strings decrypt/deobfuscator
(c) Pedro Vilaça 2020, All rights reserved.
reverser@put.as - https://reverse.put.as
reference: https://reverse.put.as/2020/09/17/evilquest-revisited/
python implementation for previous sample(s) by Scott Knight
https://github.com/carbonblack/tau-tools/tree/master/malware_specific/ThiefQuest
It is able to decrypt a single string or a whole file.
```
Usage:
-f string
file to decrypt all strings
-s string
string to decrypt
```