From time to time, we come up with interesting bits of malware that are just calling us to decode and learn more about them. This is one of those cases.
Recently, I crossed pathes with this little gem:
That snippet is encoded malicious content. The full payload is is much bigger, 12816 characters, to be exact. Seems benign, right? At least it looks interesting. So interesting that I decided to dissect it, piece by piece.