Avast researchers detailed how Visual Basic 6 (VB6) P-Code remains a viable malware platform, publishing reverse-engineering work that maps the internals of the msvbvm60.dll runtime, expands understanding of the instruction set, and improves disassembly of the language’s proprietary bytecode. The research found that VB6 P-Code is far more complex than a simple 256-opcode model, with roughly 822 unique opcode handlers after removing invalid and duplicate entries from a larger prefixed and unprefixed space. The work also documented variable-length instruction decoding, constant-pool structures, COM call resolution, and debugger-assisted analysis, while pointing to tools such as VBDec and Semi-VBDecompiler as practical references for analysts handling VB6-based malware.
Separate papers showed how attackers could exploit those gaps in tooling by hiding payload data inside VB6 executables and by manipulating P-Code streams in ways that still execute correctly at runtime but can break static analysis. Demonstrated techniques included jumps over junk bytes, jumps into argument data, invalid instruction sequences, and binary storage in resources, appended data, strings, form properties, error line tables, and other VB6-specific structures. Avast also described a method for extracting and reusing VB6 malware functions outside their original host by initializing the runtime through CreateIExprSrvObj, preserving RTMI/ProcDscInfo metadata, and invoking routines through ProcCallEngine, enabling analysts to execute malware-derived P-Code such as decryptors without fully reimplementing the runtime.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Avast Decoded published research describing how to extract and execute VB6 P-Code functions outside their original host by initializing the runtime, rebuilding required structures, and invoking ProcCallEngine. The article also highlighted use of the VBDec debugger and generator to automate extraction and patching tasks.
Avast Decoded published a reverse-engineering paper on VB6 P-Code disassembly and runtime internals, documenting opcode dispatch, argument decoding, and the complexity of the instruction set. The paper estimated about 822 unique handlers after removing invalid and duplicate entries from a theoretical maximum of 1,531 opcodes.
Avast Decoded published research concluding that VB6 P-Code can be obfuscated at the byte-stream layer. The paper demonstrated mutated samples using jump-over-junk, jumps into argument bytes, and invalid sequences that still execute correctly in the VB6 runtime.
Avast Decoded published a technical overview of how VB6 malware can embed binary data in executables, covering string encodings, opcode-based hiding, VB6 file-format structures, and PE-related storage tricks.
The researchers uploaded a mutated VB6 P-Code sample to VirusTotal so vendors could test their tooling against the demonstrated obfuscation techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
decoded.avast.io
Open sourcedecoded.avast.io
Open sourcedecoded.avast.io
Open sourcedecoded.avast.io
Open sourcesandsprite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.