VBS Stager to In-Memory C# Loader 20.08.2026 From an obfuscated VBS dropper through two PowerShell stages to a fileless C# loader that hides its strings in a DES-encrypted resource and hollows RegAsm. vbs powershell csharp process-hollowing fileless
Lowlevel Windows Functions in Powershell - REMCOS Dropper 19.07.2026 Multistage Dropper with a lot of obfuscation and evasion techniques Remcos Powershell VBS deobfuscation dropper fileless
Fileless .NET DLL - RAT 06.07.2026 A javascript file that stages Powershell and extracts a malicous .NET Dll from an image. XWORM Powershell .NET javascript Steganography
Powershell Dropper - Analysis 04.07.2026 This is my first Malware Analysis, i am trying to elaborate my thought process as well as techniques I used to get rough it. StealC Powershell Electron NSIS Golang