本文へ移動
cccskills
無料GitHub で公開

deobfuscating-malicious-powershell

Deobfuscates malicious PowerShell by decoding -EncodedCommand, reversing string and format obfuscation, resolving base64/gzip/IEX layers, and recovering the final payload and IOCs. Activates for requests to deobfuscate, decode, or analyze obfuscated PowerShell commands or scripts.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md3.4 KB
  • LICENSE340 B
  • references/api-reference.md1.4 KB
  • scripts/analyst.py3.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Deobfuscating Malicious PowerShell

When to Use

  • You captured an obfuscated PowerShell command from a log, maldoc, or phishing payload.
  • You need to recover the real intent: download URLs, dropped paths, shellcode, or next stage.
  • You are unrolling layered encoding (base64 → gzip → IEX) to reach the final script.

Do not use Invoke-Expression or run the script to "see what it does" on a working host. Decode statically; only execute in the isolated lab with logging if dynamic confirmation is required.

Prerequisites

  • Python (bundled script handles base64/gzip/deflate and common transforms), or a sandbox.
  • The command/script text captured as a string.

Safety & Handling

  • Never pipe attacker PowerShell into a live shell. Replace IEX/Invoke-Expression with output (print) when transforming.
  • Treat decoded URLs/IPs as live; defang before sharing.

Workflow

Step 1: Decode -EncodedCommand

-EncodedCommand (-enc) is base64 of UTF-16LE. Decode it first:

python scripts/analyst.py decode --encodedcommand "<base64>"

Step 2: Identify the obfuscation style

Common patterns:

String reversal      : [array]::Reverse / -join with [-1..]
Format operator      : ("{1}{0}" -f 'b','a') -> 'ab'
Char codes           : [char]104 + [char]105
Concatenation/splits : 'po'+'wer'+'shell', -split / -replace tricks
Backtick/casing noise : I`E`X, iEx, &('i'+'ex')

Step 3: Unroll encoding layers

Resolve nested FromBase64String, gzip/deflate (IO.Compression), and re-IEX layers until you reach plain script. The script peels base64/gzip layers automatically.

python scripts/analyst.py deobfuscate payload.ps1

Step 4: Neutralize execution sinks

Replace IEX, Invoke-Expression, &, and .Invoke() with a print so the recovered script is rendered, not run.

Step 5: Extract IOCs

Pull DownloadString/DownloadFile URLs, C2 hosts, dropped paths, and any embedded base64 shellcode for separate analysis.

Validation

  • The fully decoded script is human-readable PowerShell with no remaining base64 blobs.
  • Execution sinks are neutralized; nothing in your workflow actually ran the payload.
  • Extracted URLs/paths are consistent with the script's logic.

Pitfalls

  • Running the script to decode it — the fastest way to get compromised.
  • Stopping after one base64 layer when several are nested.
  • Missing UTF-16LE vs UTF-8 when decoding -enc (it is UTF-16LE).
  • Ignoring -replace/-f transforms that rebuild commands at runtime.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する