Controlled dynamic analysis produced a PowerShell script and shellcode. Script strings suggested memory allocation and reflective Windows API use. Process and registry analysis, including Procmon, showed the MSBuild chain, C2 communication and Autorun persistence in the analysis environment.
Viewed
Growing MSSP with Offensive Services
Following the MSBuild execution chain
From obfuscated PowerShell to MSBuild injection
Return to the full story ←