logo

Malware Deep Dive: Examining A PowerShell Payload

ID: 872d9a24-b636-5e40-8df6-7635baed36d2

STIX ID: report--872d9a24-b636-5e40-8df6-7635baed36d2

Feed Name: Huntress Blog

Threat Score
70/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

This report analyzes a PowerShell-based "living off the land" malware loader found via an HKLM\SOFTWARE Run key; the attacker stored UTF-16 base64 data that decodes to a gzip-compressed PowerShell script, which in turn contains base64-encoded shellcode. The shellcode uses VirtualAlloc/CreateThread and loads WinInet, indicating a downloader that contacts remote hosts to fetch additional payloads; the write-up includes decoding steps, shellcode disassembly, and demonstrates persistence and stealth techniques along with detection/remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.