
Malware Analysis: Stage 2 PowerShell Attack with Fake Cloudflare Interface and Browser Sandbox Bypass
malwarePowerShellCloudflarephishingbrowsersandboxtimeout.exenetworksecuritythreat-analysiscyberattack
The analyst uploads and executes a file called Stage 2.ps1, which triggers PowerShell execution and displays a fake Cloudflare interface. The malware initiates multiple suspicious processes including run DL32, timeout.exe, and service host.exe, along with launching Edge and Chrome browsers with their sandbox protections disabled. The analyst observes network connections being established and notes that timeout.exe appears particularly suspicious, executing from unexpected locations and performing additional malicious activities. The execution chain begins with PowerShell from the original payload, followed by timeout.exe and DXE files conducting further suspicious operations alongside standard Microsoft processes.