// the find
JohnHammond/vbe-decoder
A Python3 script to decode an encoded VBScript file, often seen with a .vbe file extension
A single-file Python3 CLI that decodes Microsoft's VBE-encoded VBScript files back into readable .vbs source. It's a straight port/cleanup of Didier Stevens' decode-vbe.py, mainly useful for malware analysts and incident responders who keep running into .vbe droppers.
Does exactly one thing and does it with zero dependencies, so it drops into any analysis environment or sandbox without a pip install. It explicitly fixes a real gap in the original Didier Stevens script by handling multiple #@~^...##@~ encoded blocks in a single file, which matters for multi-stage droppers. The CLI is minimal and sane - stdin-style single file or multiple files, output to stdout or a file.
No test suite at all for a decoder whose whole job is correctly reversing a byte-substitution table - a single off-by-one would silently corrupt output and nobody would know. No error handling visible for malformed or non-VBE input, so feeding it a plain .vbs or truncated file will likely throw a raw traceback instead of a useful message. Not packaged for pip, so it's clone-and-run only. Last commit was 2022, and the project is just two files, so this is a finished personal utility, not something with an issue tracker you'd get a response from.