> For the complete documentation index, see [llms.txt](https://0x.b4dc0.de/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0x.b4dc0.de/malware-writeups.md).

# Malware / Writeups

- [Development](https://0x.b4dc0.de/malware-writeups/development.md)
- [PowerShell Script Block Obfuscation](https://0x.b4dc0.de/malware-writeups/development/powershell-script-block-obfuscation.md)
- [VBS-JS Polyglot](https://0x.b4dc0.de/malware-writeups/development/vbs-js-polyglot.md)
- [Analysis](https://0x.b4dc0.de/malware-writeups/analysis.md)
- [AsyncRAT](https://0x.b4dc0.de/malware-writeups/analysis/asyncrat.md): AsyncRAT Infection Chain Analysis
- [Operation Duck Hunt](https://0x.b4dc0.de/malware-writeups/analysis/operation-duck-hunt.md)
- [GuLoader Script Deobfuscation](https://0x.b4dc0.de/malware-writeups/analysis/guloader-script-deobfuscation.md)
- [Creating a deobfuscator](https://0x.b4dc0.de/malware-writeups/analysis/creating-a-deobfuscator.md)
- [SmokeLoader Analysis](https://0x.b4dc0.de/malware-writeups/analysis/smokeloader-analysis.md)
- [Clearing the Smoke: A Smokeloader Analysis Part 1](https://0x.b4dc0.de/malware-writeups/analysis/smokeloader-analysis/clearing-the-smoke-a-smokeloader-analysis-part-1.md)
