logo

Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)

ID: 1a6b0bb2-e429-5cb6-b3b7-a2d4932f783c

STIX ID: report--1a6b0bb2-e429-5cb6-b3b7-a2d4932f783c

Feed Name: SANS ISC Diary

Threat Score
60/100

Date Published: 2026-04-01

Date Updated: 2026-04-19

...
...

This short technical note demonstrates how an attacker achieves persistence by copying a script into %APPDATA% and creating a Run registry entry, then uses PowerShell to remove the :Zone.Identifier alternate-data-stream to make the file appear less suspicious to DFIR tools; the script later invokes a DonutLoader payload. The write-up highlights an anti-forensics step (ADS removal) that can hinder detection and investigation of file-based malware despite claims of being "fileless."

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.