When analyzing interpreted languages like PowerShell, JavaScript, VBA/VBS, there are some handy shortcuts to dealing with obfuscated code. (NOTE: Always do this kind of analysis in a sandbox VM off of your corporate network.)
Keep Current with Paul Melson
This Thread may be Removed Anytime!
 
            Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!
 
            1) Follow Thread Reader App on Twitter so you can easily mention us!
2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll"
                @threadreaderapp unroll
              
You can practice here first or read more on our help page!