home

paste obfuscated powershell · decode base64 utf-16 · deflate gzip · concat replace char arrays · multi-pass steps · iocs · dangerous patterns · runs locally

Click ANALYZE after pasting. EncodedCommand uses UTF-16LE. Compression chains near FromBase64String are best-effort inflated — proprietary packers may need manual review.

ready