Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

GootLoaderAutoJsDecode.py

Statically deobfuscate GootLoader (GOOTLOADER) malicious JScript to recover the payload and extract C2 domains.

scriptsBlue Team
Official docs ↗Download ↗

Platforms: Linux · License: Apache License 2.0 · Last verified September 6, 2026

Statically deobfuscate GootLoader (GOOTLOADER) malicious JScript to recover the payload and extract C2 domains.

Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.

Getting started

Preinstalled on REMnux. See the official REMnux tool listing and upstream website linked above for details.

Commonly preinstalled on

REMnux

Ubuntu-based toolkit for reverse-engineering and analyzing malicious software