logo

Hiding In Plain Sight

ID: 6935fb46-384f-5e18-a5d5-e97d8e7ef821

STIX ID: report--6935fb46-384f-5e18-a5d5-e97d8e7ef821

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

This report analyzes a stealthy malware foothold that masquerades as a legitimate scheduled task (BfeOnServiceStartTypenChange), using renamed system binaries (mshta.exe and powershell.exe) to decode and execute an obfuscated PowerShell payload stored in a file that resembles an error log (c:\windows\a.chk). The author breaks down the command, explains how decimal values are converted to ASCII to reconstruct the payload, and highlights the technique of hiding in plain sight by copying legitimate task names and descriptions to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.