VIRTUAL DEOBFUSCATOR - A DARPA CYBER FAST TRACK FUNDED EFFORT

Black Hat USA 2013

Presented by: Jason Raber
Date: Thursday August 01, 2013
Time: 15:30 - 16:30
Location: Roman 1 & 3

While there has been a lot research done on automatically reverse engineering of virtualization obfuscators, there has been no approach that did not require a lot of man-hours identifying the bytecode (static approaches) or a complete recreation of the bytecode back to original source form (dynamic approaches). The tool I created, Virtual Deobfuscator, will require no static man-hours reversing for the bytecode location or how the VM interpreter works, and will recreate instructions nearly equivalent to the original instructions.

Jason Raber

Jason Raber is the founder of HexEffect, LLC, which focuses on creating novel tools and techniques for automatically reverse engineering malware and software. He enjoys bodybuilding (Yeah Buddy!), fishing, and reversing! He has presented at Black Hat 4x -Hades, Deobfuscator, QuietRIATT, and RE with hardware emulators; and at REcon twice, about a custom Linux debugger and RE with hardware emulators


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats