s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.powertrash

📛 Threat Title

Malware family: POWERTRASH

Category: POWERTRASH First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.powertrash`. Printable name: POWERTRASH.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.powertrash VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powertrash

IOC database

Type
domain
Value
ps1.powertrash
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.powertrash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powertrash

References (1)

Remediations (10)

  • web:attack.mitre.org

    A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside.

  • web:blackpointcyber.com

    FIN7 specialized in point-of-sale (PoS) malware for financial theft and fraud; however, the group was observed changing directions and getting involved in ransomware operations in 2020. The group has been observed as an affiliate with ransomware-as-a-service (RaaS) operations such as REvil and Conti; as well as developing and operating their own RaaS program, DarkSide and BlackMatter.

  • web:malpedia.caad.fkie.fraunhofer.de

    This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload. According to Mandiant's blog article: " POWERTRASH is a uniquely obfuscated iteration of a shellcode invoker included in the PowerSploit framework available on GitHub."

  • web:securityboulevard.com

    FIN7 - 2024-04 - Spear Phishing and Typosquatting Leads to POWERTRASH Deployment At the end of 2023, BlackBerry researchers identified a phishing campaign, led by the financially motivated adversary FIN7, targeting a large automotive manufacturer based in the United States.

  • web:thecyberexpress.com

    Powertrash : A heavily obfuscated PowerShell script used to reflectively load malware in memory, evading detection. Diceloader: A minimal backdoor allowing attackers to establish command and control channels and load additional modules. SSH-based backdoor: A persistence mechanism using OpenSSH and 7zip to maintain access to compromised systems.

  • web:www.attackiq.com

    Click for Larger At this stage, POWERTRASH , an in-memory dropper written in PowerShell designed to execute an embedded payload directly in memory, is deployed. The stage then gathers information about the compromised system, including its timezone, active processes, and domain administrator accounts.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.ibm.com

    A Russian advanced persistent threat group is now believed to be selling its EDR evasion tools to other attackers, creating a rapidly escalating threat.

  • web:www.mphasis.com

    In December 2023, Microsoft said it observed the attackers relying on Google ads to lure users into downloading malicious MSIX application packages, which ultimately led to the execution of POWERTRASH , a PowerShell-based in-memory dropper that's used to load NetSupport RAT and Gracewire.

  • web:www.sentinelone.com

    Our analysis of the Timeline of Powertrash -Packed Malware Families revealed a consistent pattern in the usage of the group's C2 implants. Historically, FIN7 has utilized Carbanak, a privately developed and fully featured C2 framework, to carry out their malicious operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.