
An IDA pro python script to decrypt Qbot malware strings.

Tested and working with Qbot OBAMA111 https://www.malware-traffic-analysis.net/2021/10/07/index.html

Markdown Monster icon

Before using the script make sure to fix the calling convention of the decryption functions like below.

Markdown Monster icon

Markdown Monster icon

All the decrypted string will be placed as comment next to the decrypt string function call.

Markdown Monster icon


GitHub - StuckinVim-Forever/Qbot-Strings-Decrypter at pythonawesome.com
An IDA pro python script to decrypt Qbot malware string - GitHub - StuckinVim-Forever/Qbot-Strings-Decrypter at pythonawesome.com