<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Deobfuscation-Lab on Matt Swann — Detection Engineering &amp; Threat Intel</title><link>http://mattswann.dev/tags/deobfuscation-lab/</link><description>Recent content in Deobfuscation-Lab on Matt Swann — Detection Engineering &amp; Threat Intel</description><image><title>Matt Swann — Detection Engineering &amp; Threat Intel</title><url>http://mattswann.dev/og-image.png</url><link>http://mattswann.dev/og-image.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 22 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="http://mattswann.dev/tags/deobfuscation-lab/index.xml" rel="self" type="application/rss+xml"/><item><title>Unpacking QuimaRAT: From VBScript Dropper to a 255-Packet Offensive Framework</title><link>http://mattswann.dev/posts/quimarat-vbs-dropper/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>http://mattswann.dev/posts/quimarat-vbs-dropper/</guid><description>QuimaRAT is a new RAT being touted as a powerful cross-platform RAT capable of infecting Windows, MacOS, and Linux devices. While this is certainly true, it also happens to be quite an understatement. In this article we will unpack a VBScript dropper and analyze the subsequent JAR payload.</description></item><item><title>When Comments Aren't Comments: Decoding An Obfuscated JavaScript Sample</title><link>http://mattswann.dev/posts/when-comments-arent-comments-obfuscated-javascript/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>http://mattswann.dev/posts/when-comments-arent-comments-obfuscated-javascript/</guid><description>An obfuscated JavaScript sample was observed on a device with an oddly large comment block at the top of the code. Students of programming are often taught that comments are not part of code itself and serve no other purpose other than to provide explanations for code blocks. In this article, we explore why that isn&amp;rsquo;t always true.</description></item><item><title>AppDomainManager Injection — Bend .NET Assemblies to Your Will</title><link>http://mattswann.dev/posts/appdomainmanager-injection/</link><pubDate>Thu, 12 Feb 2026 23:26:36 -0700</pubDate><guid>http://mattswann.dev/posts/appdomainmanager-injection/</guid><description>A deep dive into AppDomainManager injection (T1574.014): how attackers use .NET&amp;rsquo;s own extensibility model to proxy execution of malicious assemblies through legitimate signed binaries, and what defenders can — and can&amp;rsquo;t — do about it.</description></item><item><title>Advent of Cyber 2025 Day 21 — Malware Analysis Bonus Challenge</title><link>http://mattswann.dev/posts/advent-of-cyber-2025-day21-bonus/</link><pubDate>Sun, 21 Dec 2025 23:39:55 -0700</pubDate><guid>http://mattswann.dev/posts/advent-of-cyber-2025-day21-bonus/</guid><description>A walkthrough of the TryHackMe Advent of Cyber 2025 Day 21 bonus challenge: peeling back a multi-layer HTA payload through VBScript analysis, Base64 decoding, and XOR decryption to uncover a hidden PNG.</description></item></channel></rss>