14th Working Conference on Reverse Engineering (WCRE 2007)
Deobfuscator: An Automated Approach to the Identification and Removal of Code Obfuscation
Vancouver, BC, Canada
October 28-October 31
ISBN: 0-7695-3034-6
The Deobfuscator is an IDA Pro plug-in that neutralizes anti-disassembly code and transforms obfuscated code to simplified code in the actual binary. This plug-in is used in conjunction with a binary injector to remove obfuscated code and replace it with a simplified, transformed equivalent. We developed this tool in assessing strengths of protections and malware analysis for DoD government entities and commercial companies.
Citation:
Jason Raber, Eric Laspe, "Deobfuscator: An Automated Approach to the Identification and Removal of Code Obfuscation," wcre, pp.275-276, 14th Working Conference on Reverse Engineering (WCRE 2007), 2007