Hiding In Plain Sight
ID: 6935fb46-384f-5e18-a5d5-e97d8e7ef821
STIX ID: report--6935fb46-384f-5e18-a5d5-e97d8e7ef821
Feed Name: Huntress Blog
This report analyzes a stealthy malware foothold that masquerades as a legitimate scheduled task (BfeOnServiceStartTypenChange), using renamed system binaries (mshta.exe and powershell.exe) to decode and execute an obfuscated PowerShell payload stored in a file that resembles an error log (c:\windows\a.chk). The author breaks down the command, explains how decimal values are converted to ASCII to reconstruct the payload, and highlights the technique of hiding in plain sight by copying legitimate task names and descriptions to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
