VBS Stager to In-Memory C# Loader
From an obfuscated VBS dropper through two PowerShell stages to a fileless C# loader that hides its strings in a DES-encrypted resource and hollows RegAsm.
A malware analysis collection and learning timeline. I write about my process and thoughts while taking apart loaders, droppers, and other malware samples.