The Yoroi-Cybaze ZLAB dissected the VBS script embedded into the zip archives delivered to the victims of a recent attack. The inner powershell payload was designed to download the malicious Gootkit binary from the attackers infrastructure. This inner script was carefully obfuscated in a clever and unseen way. The attack wave contained some interesting techniques need to look into further, especially regarding the obfuscation used to hide the malicious dropping infrastructure. The Powershell code executed by the initial VBS code appears as following:”]
Source: https://securityaffairs.co/wordpress/78574/malware/dissecting-powershell-obfuscation.html

