Practical Binary Emulation and Taint Analysis for De-obfuscation
This paper presents a practical taint-analysis-based approach for deobfuscating protected binaries and malware. The method tracks selected taint sources, such as global variables, memory addresses, or function arguments, as they propagate through registers, memory, and instructions. By combining binary emulation, Triton-based taint tracking, and custom trace logic, the approach can identify junk instructions, fake control flow, encrypted code blocks, and cross-function obfuscation. Three case studies—Flare-On Challenge 7, Smoke Loader, and FindDraft Loader—demonstrate how taint analysis improves decompiler output and reduces manual reverse engineering effort by separating real program behavior from obfuscation noise.

Tạ Đăng Vinh- VNPT Cyber Immunity
Tạ Đăng Vinh, Threat Analyst at VNPT Cyber Immunity specializing in Cyber Threat Intelligence, malware analysis, and reverse engineering. My work focuses on investigating malware and adversary activity, extracting IOCs, mapping TTPs to MITRE ATT&CK. My interests include malware research, reverse engineering, CTF and tooling development.

Mr Đoàn Minh Long
Doan Minh Long is a threat analyst with experience in reverse engineering, malware analysis, and tracking threat actors targeting the Southeast Asia region.