Java Deobfuscator & Decompiler Helper
Detect and decode obfuscated patterns in Java source code. Identifies Unicode escape sequences, hex string encodings, obfuscated numeric literals, Base64 encoded strings, and char array concatenation. Shows every detection with encoded and decoded values side by side, confidence ratings, and source context. Free, private, and no signup required.
Detect and decode obfuscated patterns in Java source code. Identifies Unicode escapes, hex string encodings, obfuscated numeric literals, Base64 encoded strings, and char array concatenation. Shows encoded and decoded values side by side with detection confidence.
Paste Java code above and click Analyze Java Code to detect and decode obfuscated patterns. The tool identifies Unicode escapes, hex string encodings, obfuscated numeric literals, Base64 strings, and char array concatenation. Try loading an example to see how it works!
Features
5 Obfuscation Pattern Detectors
Automatically detects Unicode escape sequences (\\uXXXX), hex string decoding, obfuscated numeric literals (hex, octal, binary), Base64 encoded strings, and char array concatenation. Each method uses its own specialized detection engine with regex and heuristic pattern matching.
Side-by-Side Encoded & Decoded View
Every detected obfuscation shows the original encoded value alongside the decoded result. Encoded values appear in monospace with character-length stats, while decoded values are visually highlighted for rapid scanning and comparison.
Obfuscated Number Unpacking
Detects and decodes obfuscated numeric literals including hex (0xFF), octal (0377), binary (0b11111111), and bitwise-disguised expressions. Shows the original numeric value alongside its obfuscated representation with full context.
Browser-Local Privacy
All Java deobfuscation processing runs entirely in your browser. Your Java source code, detected obfuscation patterns, and decoded values never leave your device. No server uploads, no data collection, no API calls of any kind.
Use Cases
Malware & Payload Analysis
Analyze obfuscated Java malware, droppers, and backdoors to extract hidden C2 URLs, encryption keys, IP addresses, and configuration strings. Many Java malware samples use Unicode escapes and Base64 to hide strings from static analysis tools.
Decompiled Code Recovery
When decompiling obfuscated Java JAR files, tools like CFR, Procyon, and Fernflower often produce code with obfuscated identifiers and encoded strings. Use the deobfuscator to clean up and understand the decompiled output.
Minecraft Mod & Plugin Analysis
Analyze obfuscated Minecraft mods, Bukkit/Spigot plugins, and Forge mods protected by tools like ProGuard, Allatori, or custom obfuscators. Detect hidden API keys, webhook URLs, and premium feature gates.
Android APK String Extraction
Extract and decode obfuscated strings from Android APK DEX bytecode decompiled to Java. Identify hidden ad network IDs, tracking URLs, API endpoints, and hardcoded credentials in obfuscated Android applications.
Enterprise Code Audit
During security code audits of Java enterprise applications, detect obfuscated configuration values like database URLs, service endpoints, JNDI lookups, and LDAP filters hidden through string encoding techniques.
Educational Tool for Java Obfuscation
Learn how Java obfuscation techniques work by seeing encoded strings and numbers decoded in real-time. Understand how Unicode escapes, hex strings, Base64, and char array concatenation are used to hide data from casual inspection.
About Java Deobfuscation & Decompilation
What Is Java Obfuscation?
Java obfuscation transforms Java bytecode or source code to make it significantly harder to reverse-engineer while preserving functionality. Unlike compiled C++ or Rust, Java bytecode retains rich metadata including class names, method signatures, constant pool entries, and line number tables — all of which can be exploited for reverse engineering. Common obfuscation techniques include Unicode escapes(\\u0048 instead of "H"), hex strings (byte arrays from hex literals),obfuscated numbers (hex, octal, binary, bitwise expressions), Base64 encoding, and char array concatenation (building strings from individual characters). Understanding these techniques is the first step in deobfuscating Java code effectively.
How Our Java Deobfuscator Works
The deobfuscator scans Java source code using specialized pattern detectors for each known obfuscation technique. For Unicode escapes, it extracts \\uXXXX sequences and converts them to the corresponding Unicode characters using String.fromCodePoint(). For hex strings, it detects hex digit pairs and Base64-encoded strings within string literals and converts them to readable text. For obfuscated numbers, it identifies hex (0x), octal (0-prefixed), and binary (0b) literals and evaluates them to their decimal equivalents. For char arrays, it finds sequential character array initializations and concatenation patterns, collecting the characters to reconstruct hidden strings. Each detection includes surrounding source context and line numbers.
Java-Specific Deobfuscation Considerations
Java obfuscation has several unique characteristics. Unicode escapes are processed during the Java lexer phase — before the compiler even sees the code — meaning \\u0048is equivalent to 'H' at the source level. Hex strings in Java often appear as new String(byte[]101)or similar constructions. Obfuscated numbers in Java use 0x prefix for hex, leading zero for octal, and 0b for binary. ProGuard, the most common Java obfuscator, primarily renames classes, methods, and fields but also supports string encryption through third-party plugins like Stringer or DexGuard. The deobfuscated output helps you understand what the code would look like before obfuscation was applied.
Privacy & Security
This tool runs entirely in your browser. Your Java source code, detected obfuscation patterns, and decoded values are never uploaded to any server, stored in any database, or transmitted over any network. All parsing, pattern matching, and decoding execute locally on your device using client-side JavaScript. There are no API calls, analytics tracking, cookies, or data collection of any kind. This makes it completely safe for analyzing proprietary Java code, decompiled APK sources, malware samples, or confidential enterprise applications.