Open-source atomic malware analysis

Analyze another

11-x64/Win11_25H2_English_x64_v2/sources/install.wim.d/4/Windows/WinSxS/wow64_microsoft.secureboot.commands_31bf3856ad364e35_10.0.26100.7920_none_de1c8f1108545493/r

POWERSHELL
Verdict: SUSPICIOUS
AI Obfuscated PowerShell payload
Mal-ecule
O(As)Md
Size 173 B download
First seen 11 days ago
Analyzed 2 days ago
Ecosystem windows
Source microsoft.com
Many single-character variables: SecureBoot.psd1:0x0
SecureBoot.psd1 powershell
1 '/�PA31���ޱ�P Many single-character variables
2 `} @�� v2
3 3�A�q���*+k<r��+�V��-q�`���"�  g8u��e�~��x�b
4 �t��ɉ�q�vӝ�O���j
5 ����������(@�������� �푙���Ev�����������������

Objectives

Metadata

Identity

SHA-256 a3afa2d92ee0d1c2f8bbd995ead2acfb5949da3bd50fd89a2d8a4d859be73ccb
Filename SecureBoot.psd1
Package 11-x64/Win11_25H2_English_x64_v2/sources/install.wim.d/4/Windows/WinSxS/wow64_microsoft.secureboot.commands_31bf3856ad364e35_10.0.26100.7920_none_de1c8f1108545493/r

Origin

Source harvest
Feed osimage
Ecosystem windows
Domain microsoft.com

Timeline

First seen 3 Aug 2026 12:21 UTC
First analyzed 12 Aug 2026 02:26 UTC
Last analyzed 12 Aug 2026 02:26 UTC
Last updated 12 Aug 2026 02:26 UTC

Labeling

Label good
Label source harvest
Traits version 73866