ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

[Question] .NET ConfuserEx deobfuscation


  • Please log in to reply
[Question] .NET ConfuserEx deobfuscation

#1

0xExpl0it
0xExpl0it
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 8
Threads: 1
Joined: Nov 08, 2021
Credits: 0
Two years registered
#1

hey guys,

Hope you can help me out here,
I'm trying to deobfuscate a .NET malware that is obfuscated using ConfuserEx,
I've looked around in the internet and found some related tools of CodeCracker but they didn't really helped out.
here are some screenshots to show off the code structure abit:

https://ibb.co/rfJF6Mb

https://ibb.co/dMD0c8G

https://ibb.co/8zvVPJB


  • 0

#2

cardmani
cardmani
    Offline
    220
    Rep
    557
    Likes

    Admin

Posts: 2047
Threads: 213
Joined: May 27, 2018
Credits: 2

Five years registered
#2

It's all bout understanding how this works. Eg

Those u206D are just hex. You can write a script that converts all of them to a string and see if you can get any closer to deobfuscating


  • 0

WUCjhrZ.gif


#3

0xExpl0it
0xExpl0it
    Offline
    0
    Rep
    0
    Likes

    Lurker

Posts: 8
Threads: 1
Joined: Nov 08, 2021
Credits: 0
Two years registered
#3

It's all bout understanding how this works. Eg

Those u206D are just hex. You can write a script that converts all of them to a string and see if you can get any closer to deobfuscating

I've tried this, but they're just not making any sense:
the string: 
 

\u202B\u206A\u200C\u200B\u202A\u206D\u200F\u206A\u200E\u200D\u206B\u200B\u206F\u206A\u206C\u202D\u206E\u200E\u206B\u206D\u202E\u200E\u202C\u202C\u200F\u200F\u206D\u206D\u206F\u206C\u206F\u202E\u202D\u200D\u206C\u200D\u200D\u200D\u202E\u202A\u202E

traslates to:

 + j . . * m . j . 
 k . o j l - n . k m . . , , . . m m o l o . - 
 l 
 
 
 . * .

  • 0

#4

Israel
Israel
    Offline
    212
    Rep
    92
    Likes

    :jen:

Posts: 154
Threads: 53
Joined: Sep 14, 2018
Credits: 0

Five years registered
#4

there are a lot of tools on github to deobfuscate not modded confuserex obfuscator and a lot of videos on youtube.

if you search hard enough you will find everything you are looking for.
solarpower is right, it is hex and you can convert it to a string and get the function's name but how would that help you?

functions' names are randomly generated to make it "harder" to deobfuscate.


  • 0

israel@nulled.to



 Users browsing this thread: