logo

ThreatOps Analysis: Keyed Malware | Huntress

ID: 5ab0710f-922d-5920-a2cc-81d4bfb1db45

STIX ID: report--5ab0710f-922d-5920-a2cc-81d4bfb1db45

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

The report describes a PowerShell-based, environment-keyed malware stager that derives a decoding key from host identifiers (hostname, username, domain, and IP) to decode a hex payload; when decoded the stager downloads and executes Meterpreter directly in memory, illustrating a targeted evasion technique and detailing how analysts decoded the payload without running it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.