Group Purchasing
Group Purchasing

DeScrypt: A Multi-Tool Framework for Automated Unpacking and Analysis of Malicious Scripts

DeScrypt: A Multi-Tool Framework for Automated Unpacking and Analysis of Malicious Scripts (PDF, 0.83MB)Published: 28 Sep, 2026
Created by:

Scripting languages are increasingly dominant malware vectors that often employ layered obfuscation techniques to slow down manual analysis by reverse engineers and to prevent pattern recognition. Existing deobfuscators are often developed for specific encoding mechanisms or programming languages, resulting in complex analysis pipelines that require multiple tools or techniques to analyze samples fully. DeScrypt is a multi-tool deobfuscation orchestration framework that integrates native decoders and available tools to automatically select and invoke plausible decoding techniques, including chains that span multiple languages within a single sample.

This paper evaluates its effectiveness on 1,000 malicious samples (500 JS / 500 PS) and compares the results with 200 benign samples. DeScrypt invoked at least one tool in 75.9% of samples, with 33.9% achieving a clean terminal payload and a 1% false-positive rate for benign samples. The orchestration extends coverage beyond a single-engine tool and has shown greater effectiveness for JavaScript samples than for PowerShell samples. A majority of samples that scored zero had nonetheless been unpacked at least once, highlighting the decoupling of effective deobfuscation from the detection of malicious scripts.