Reverse-engineering researcher Tim Blazytko published two complementary binary-analysis approaches aimed at speeding malware triage and firmware investigation. One method identifies likely API or otherwise central routines by ranking functions based on how many distinct callers invoke them, a heuristic designed for stripped or statically linked binaries where symbols and library boundaries are missing. In testing on Linux Coreutils ls, an ARMv8-M firmware image, a statically linked XOR DDoS sample, and PlugX malware, the technique surfaced memory, string, logging, cryptographic, and interrupt-related routines, and in PlugX highlighted an API-hashing workflow involving LoadLibraryA, a modified CRC32 routine, and resolution of GetProcAddress from kernel32.
Blazytko also released Obfuscation Detection v2.4, a Binary Ninja plugin that flags obfuscated or otherwise unusual code constructs to help analysts prioritize suspicious functions. The plugin uses heuristics to detect patterns such as state machines, cryptographic routines, string decryption logic, overlapping instructions, uncommon instruction sequences, recursive functions, functions without callers, high-entropy sections, and potential RC4 implementations, and it supports both GUI and headless use with JSON output for automation. Together, the releases provide architecture-agnostic techniques for identifying important code paths and obfuscation artifacts in malware samples and embedded firmware.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The GitHub repository for Obfuscation Detection v2.4 documented a Binary Ninja plugin by Tim Blazytko for identifying obfuscated code and unusual constructs in binaries. The documented heuristics included state machine, complex function, uncommon instruction sequence, overlapping instruction, and most-called-function detection, along with headless and JSON output support.
Tim Blazytko published a blog post describing a reverse-engineering heuristic that ranks functions by the number of distinct callers to identify important API-related routines in binaries. The post evaluated the approach on Linux Coreutils, XOR DDoS malware, embedded firmware, and PlugX malware samples.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.