VBA Beautifier Package

We are happy to announce the beta release for commercial licenses of the VBA Beautifier package. It provides automated beautification and deobfuscation for VBA (Visual Basic for Applications) and VBS (VBScript) code, the most common macro language found in malicious Office documents.

VBA macros remain one of the primary initial access vectors in the threat landscape. Malware authors routinely apply layers of obfuscation. Manually cleaning up these scripts is tedious and error-prone. The VBA Beautifier helps to automate this process, turning obfuscated macro code into clean, readable output.

RedLine Stealer Dropper

An interesting sample containing a number of different obfuscation techniques. In this article we analyze the dropper in detail and reach the final stage.

SHA256: 0B93B5287841CEF2C6B2F2C3221C59FFD61BF772CD0D8B2BDAB9DADEB570C7A6

The first file we encounter is a OneNote document. If the “OneNote Format” package is installed, all files are automatically extracted.

Continue reading “RedLine Stealer Dropper”