looking at some malware that has a string encryption routine and a string decryption routine

it encrypts a string and immediately decrypts it

the original string is there in the binary

(all these pairs of functions implement the same silly XOR algorithm in slightly different code. yes, i've lifted them to LLVM IR to check if they really do that. yes, they do)

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/whitequark/statuses/114394425225324261 on your instance and quote it. (Note that quoting is not supported in Mastodon.)