Developed this when I encountered a sophisticated sample using `%=exitcodeascii%` with subshells for obfuscation, and it works like a charm so far!
Give it a look and share any thoughts, I'm opening to adding any missing functionality.
Revamped a batch deobfuscation script to add a lot of additional functionality, check it out here to help make sense of detected malware!
github.com/TargetPackage/bat…