TF-MAL-ps1.powertrash
📛 Threat Title
Malware family: POWERTRASH
Description
ThreatFox malware family `ps1.powertrash`. Printable name: POWERTRASH.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.powertrash
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powertrash
IOC database
- Type
- domain
- Value
ps1.powertrash- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.powertrash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powertrash
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside.
-
web:blackpointcyber.com
FIN7 specialized in point-of-sale (PoS) malware for financial theft and fraud; however, the group was observed changing directions and getting involved in ransomware operations in 2020. The group has been observed as an affiliate with ransomware-as-a-service (RaaS) operations such as REvil and Conti; as well as developing and operating their own RaaS program, DarkSide and BlackMatter.
-
web:malpedia.caad.fkie.fraunhofer.de
This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload. According to Mandiant's blog article: " POWERTRASH is a uniquely obfuscated iteration of a shellcode invoker included in the PowerSploit framework available on GitHub."
-
web:securityboulevard.com
FIN7 - 2024-04 - Spear Phishing and Typosquatting Leads to POWERTRASH Deployment At the end of 2023, BlackBerry researchers identified a phishing campaign, led by the financially motivated adversary FIN7, targeting a large automotive manufacturer based in the United States.
-
web:thecyberexpress.com
Powertrash : A heavily obfuscated PowerShell script used to reflectively load malware in memory, evading detection. Diceloader: A minimal backdoor allowing attackers to establish command and control channels and load additional modules. SSH-based backdoor: A persistence mechanism using OpenSSH and 7zip to maintain access to compromised systems.
-
web:www.attackiq.com
Click for Larger At this stage, POWERTRASH , an in-memory dropper written in PowerShell designed to execute an embedded payload directly in memory, is deployed. The stage then gathers information about the compromised system, including its timezone, active processes, and domain administrator accounts.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.ibm.com
A Russian advanced persistent threat group is now believed to be selling its EDR evasion tools to other attackers, creating a rapidly escalating threat.
-
web:www.mphasis.com
In December 2023, Microsoft said it observed the attackers relying on Google ads to lure users into downloading malicious MSIX application packages, which ultimately led to the execution of POWERTRASH , a PowerShell-based in-memory dropper that's used to load NetSupport RAT and Gracewire.
-
web:www.sentinelone.com
Our analysis of the Timeline of Powertrash -Packed Malware Families revealed a consistent pattern in the usage of the group's C2 implants. Historically, FIN7 has utilized Carbanak, a privately developed and fully featured C2 framework, to carry out their malicious operations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.