Malware-Analysis.
138donut-janky-decrypter. Decrypter for payloads created with the donut shellcode tool
8astaroth-deobfuscator. IDA python script for deobfuscating Astaroth/Guildma injector DLL
8KPOT-string-decrypter. IDA python scripts to decrypt strings from KPOT and set those as comments
6ousa-decrypt. Simple C program for decrypting Ousaban/Javali encrypted archive payloads
5Astaroth-string-decrypt. Ida python script for automating string decryption of Astaroth/Guildma samples
4asta-decrypt.py. Python script for decrypting Astaroth/Guildma encrypted final stage (written to disk as db.temp)
4br-banker-decrypter. Simple C++ decrypter+decompresser for brazilian banking malware payloads
3amadey-string-renamer. Ida python script to rename Amadey's stdstrings structs to the string assigned to them
2delphi-crypt-finder. Python
2ousa-decrypt.py. Python version of the code for decrypting Ousaban/Javali encrypted archive payloads
1