本文へ移動
cccskills
無料GitHub で公開

analyzing-malicious-vbscript-and-wsf

Analyzes malicious VBScript, WSF, and HTA scripts: parsing WSF/HTA containers, decoding VBScript.Encode (#@~^) and string obfuscation, and identifying WScript.Shell/ActiveX abuse to recover dropper behavior. Activates for requests to analyze VBScript, decode a WSF/HTA, or investigate a Windows Script Host dropper.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.0 KB
  • LICENSE340 B
  • references/api-reference.md1.3 KB
  • scripts/analyst.py2.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Analyzing Malicious VBScript and WSF

When to Use

  • You have a .vbs, .wsf, or .hta delivered via phishing and need its real behavior.
  • You must decode VBScript.Encode-obfuscated script (the #@~^ marker) or string obfuscation.
  • You are identifying WScript.Shell/ActiveX-based dropper actions and IOCs.

Do not use wscript/cscript/mshta to run the script for analysis — that executes the dropper. Decode and read it statically.

Prerequisites

  • A static decoder (Python) or a script sandbox; the sample handled inertly in the lab.

Safety & Handling

  • Never run the script with Windows Script Host (wscript/cscript/mshta).
  • Defang recovered URLs; store dropped payloads password-protected.

Workflow

Step 1: Parse the container

For WSF, parse the XML <job>/<script> elements (a WSF can bundle multiple languages). For HTA, separate the HTML wrapper from the <script> body.

python scripts/analyst.py analyze sample.wsf

Step 2: Decode VBScript.Encode

If you see the #@~^ header, decode the Microsoft Script Encoder stream back to source.

Step 3: Unroll string obfuscation

Resolve Chr()/Asc() builds, string concatenation, and Replace()-based deobfuscators to reveal commands and URLs.

Step 4: Identify dropper actions and IOCs

Find CreateObject("WScript.Shell"), Run/Exec, ADODB/MSXML download patterns, and PowerShell hand-offs; recover URLs/paths, defang, and route payloads onward.

Validation

  • WSF/HTA containers are decomposed into their script bodies (all jobs/languages).
  • VBScript.Encode streams are decoded to readable source.
  • Dropper actions and IOCs are recovered without executing the script.

Pitfalls

  • Executing with wscript/mshta to "see" behavior, infecting the host.
  • Missing one <script> block in a multi-job WSF.
  • Overlooking the #@~^ encoded section and analyzing only the cleartext stub.

References

  • See references/api-reference.md for the WSF/VBScript decoder.
  • Windows Script Host docs and the Script Encoder format (linked in frontmatter).

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する