I analysed a client-supplied ZIP sample following a CrowdStrike detection. It contained obfuscated PowerShell saved with a .cmd extension. I reformatted the code and renamed variables to expose the decoding and execution functions, then changed the execution path to print decoded commands for inspection.
That exposed the first stage's download behaviour and the source of its second-stage files. The later code was more heavily obfuscated, so I moved to controlled dynamic analysis. It dropped another PowerShell script and shellcode; strings in the script suggested memory allocation and reflective loading of Windows API functions.
I used Procmon alongside analysis of the staged payload to follow process and registry activity. In the analysis environment, the chain involved a suspended msbuild.exe process, shellcode loading into its memory and subsequent execution. The process then communicated with a command-and-control server and established persistence through Autorun registry keys.
I compared this behaviour with the client endpoint evidence. CrowdStrike had interrupted the chain: the records showed no corresponding MSBuild activity, C2 traffic or Autorun persistence. I documented the execution stages and behaviours for detection work, clearly separating controlled-analysis observations from activity evidenced on the client endpoint.
Closer to the work
Obfuscation and conflicting product verdicts
The ZIP contained obfuscated PowerShell carrying a .cmd extension. I refactored the script with clearer spacing and variable names, identified its decoding and execution functions, and changed the execution function to emit the decoded commands for inspection. This exposed the second-stage download behaviour without relying on the file extension to identify the content.
Open this detail ↗Decoding and controlled execution
I used controlled dynamic analysis for the more heavily obfuscated second stage. It produced a PowerShell script and shellcode. Script strings suggested memory allocation and reflective Windows API loading; process and registry observations, including Procmon, helped reconstruct the MSBuild execution chain, C2 communication and Autorun persistence. These findings came from the analysis environment.
Open this detail ↗Sample behaviour and endpoint activity
I checked the client endpoint for the behaviours seen during controlled execution. The records did not show corresponding MSBuild activity, C2 communication or Autorun persistence after CrowdStrike interrupted execution. The resulting report explained the staged loader and its detection-relevant behaviour without treating laboratory execution as proof that the client experienced every stage.
Open this detail ↗Skills established through this work