amsi-bypass 4
- VioletRAT v6: A WinRAR-Spoofed VB.NET RAT With a 110-Command C2
- VerShadow / FUD Crypt: A MinGW VERSION.dll Carrier With A Catbox Fallback And A Live Test Payload
- DcRAT in 48KB: Cracking the Config, Mapping the Plugin Loader, and Why the Stub IS the Malware
- Stage1 (22.exe) Loader Reversing, Part I: Stage Decryption, Evasion, and Attribution