VBA Stomping
실습
https://github.com/mgeeky/VisualBasicObfuscator.git
# range() 함수와 관련해서 간단한 수정을 하면 제대로 실행된다.
647# for s in range(len(longLine) / SPLIT + 1):
# 난독화 진행
┌──(root㉿kali)-[/opt/VisualBasicObfuscator]
└─# python3 obfuscate.py payload.vbs -o payload-obfuscated.vbs
:: Visual Basic script obfuscator for thy red teaming needs!
Mariusz Banach / mgeeky, '17, '20; <mb [at] binary-offensive.com>
v: 0.2
[+] Input file: payload.vbs
[+] Output file: payload-obfuscated.vbs
[+] Input file length: 1205
[+] Obfuscated file length: 5742
[+] Obfuscated code has been written to:
payload-obfuscated.vbs



분석/대응 방안

레퍼런스
Last updated