Malware Deep Dive: Examining A PowerShell Payload
ID: 872d9a24-b636-5e40-8df6-7635baed36d2
STIX ID: report--872d9a24-b636-5e40-8df6-7635baed36d2
Feed Name: Huntress Blog
This report analyzes a PowerShell-based "living off the land" malware loader found via an HKLM\SOFTWARE Run key; the attacker stored UTF-16 base64 data that decodes to a gzip-compressed PowerShell script, which in turn contains base64-encoded shellcode. The shellcode uses VirtualAlloc/CreateThread and loads WinInet, indicating a downloader that contacts remote hosts to fetch additional payloads; the write-up includes decoding steps, shellcode disassembly, and demonstrates persistence and stealth techniques along with detection/remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
