
Analysis of a Multi-Stage PowerShell Payload Delivery Chain
cybersecuritypowershellmalware_analysisobfuscationIOCsthreat_intelligence
The post details the analysis of a multi-stage PowerShell payload delivery chain that uses heavily obfuscated loaders and remotely hosted payloads. The investigation includes techniques such as PowerShell deobfuscation, hidden execution, Base64/XOR decoding, and a decoy 'Verification complete!' prompt. Initial indicators of compromise (IOCs) identified are the IP address 203[.]188[.]171[.]166 and the domain dorenzaa[.]com.