Malware Analysis / Incident Response

Unpack a staged PowerShell malware chain

I deobfuscated a PowerShell loader and traced MSBuild, C2 and Autorun behaviour through controlled analysis, then checked which stages appeared in client telemetry.

Growing MSSP with Offensive ServicesHands-on malware analysis and incident investigation2 min read

I analysed a client-supplied ZIP sample following a CrowdStrike detection. It contained obfuscated PowerShell saved with a .cmd extension. I reformatted the code and renamed variables to expose the decoding and execution functions, then changed the execution path to print decoded commands for inspection.

That exposed the first stage's download behaviour and the source of its second-stage files. The later code was more heavily obfuscated, so I moved to controlled dynamic analysis. It dropped another PowerShell script and shellcode; strings in the script suggested memory allocation and reflective loading of Windows API functions.

I used Procmon alongside analysis of the staged payload to follow process and registry activity. In the analysis environment, the chain involved a suspended msbuild.exe process, shellcode loading into its memory and subsequent execution. The process then communicated with a command-and-control server and established persistence through Autorun registry keys.

I compared this behaviour with the client endpoint evidence. CrowdStrike had interrupted the chain: the records showed no corresponding MSBuild activity, C2 traffic or Autorun persistence. I documented the execution stages and behaviours for detection work, clearly separating controlled-analysis observations from activity evidenced on the client endpoint.

Closer to the work

Obfuscation and conflicting product verdicts

The ZIP contained obfuscated PowerShell carrying a .cmd extension. I refactored the script with clearer spacing and variable names, identified its decoding and execution functions, and changed the execution function to emit the decoded commands for inspection. This exposed the second-stage download behaviour without relying on the file extension to identify the content.

Open this detail ↗
Decoding and controlled execution

I used controlled dynamic analysis for the more heavily obfuscated second stage. It produced a PowerShell script and shellcode. Script strings suggested memory allocation and reflective Windows API loading; process and registry observations, including Procmon, helped reconstruct the MSBuild execution chain, C2 communication and Autorun persistence. These findings came from the analysis environment.

Open this detail ↗
Sample behaviour and endpoint activity

I checked the client endpoint for the behaviours seen during controlled execution. The records did not show corresponding MSBuild activity, C2 communication or Autorun persistence after CrowdStrike interrupted execution. The resulting report explained the staged loader and its detection-relevant behaviour without treating laboratory execution as proof that the client experienced every stage.

Open this detail ↗

Skills established through this work

This work connects to

SOC & incident response

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.