T1059.001 PowerShell in real malware
ATT&CK technique T1059.001 PowerShell appears in 413 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.4% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 7 prior). Most associated families: Base64, Avlj, AgentTesla, HUILoader, Lazy.
Tactics: execution
Prevalence in the corpus
- Samples exhibiting T1059.001: 413
- Share of analyzed corpus: 0.4%
- Last 7 days: 0 · prior 7 days: 7 (falling)
Malware families using T1059.001
- Base64 - 21 samples
- Avlj - 14 samples
- AgentTesla - 13 samples
- HUILoader - 11 samples
- Lazy - 9 samples
Example samples
- 7b5e3c1c06d82b3e7309c258dfbd4bfcd476c8ffcb4cebda76146145502a5997.bin - malicious
- a3676562571f48c269027a069ecb08ee08973b7017f4965fa36a8fa34a18134e.bin - malicious
- Aurora15Connector.exe - malicious
- 95089d_ea02f0a968c145c49d32b7f52fb616ae.pdf - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- KeePass.exe - malicious
- 183409d79cfd80dca36a796b541e58f6285c0a01eac0c8e1dba77c9485a83499 - malicious
- 1d76cbe508c01b74ee0ddf5040ddc3077bbcc0d90a809e66a33134f70484e5f7 - malicious
- 9a630b8f2ddeed59e50aef8c3ce6e68821667b78948f8fb82e90624fef758bed - malicious
- e90ebab1189bde368929f30615cfa89958263e3a96216e9ea355651ae5eb844d - malicious
- ALMI HYDRA REQUISITION 0015-SP205005.exe - malicious
- 925ad00081c7bceb109c86baed9bf5904dc6e018515416b98169d1c9ca1026aa - malicious
- 4ed8dcd31f3a0c01882abc9aed586af6064dd1048d041491571aee475aa8395d - malicious
- c261d38419991cfdbd46ef65acfa3668340b9cfa31e82d2137c3d355a0d5a50b - malicious
- f53693e9871d74c13b61a15b09b430855dde705fa42f4a8b56fbf82bcd151f15 - malicious
- 011bcca8feebaed8a2aa0297051dfd59595c4c4e1ee001b11d8fc3d97395cc5c - malicious
- e82cffa8438ae2618029d2025d4b0fd8abbc2e4aab254591c9c7270df1d59e13 - malicious
- 6385c65829a20f091c9ad2d499661807bffeef1e83af820bca94eab67cb6d01b - malicious
- 3e5ac7b07aad0ac1cf03f34de22eeca807515612d9a5368b3770401626017cda - malicious
- ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5 - malicious
- a54441cfa0cd8efa6e4e489a43cb1d63b1a89d94547523c264f2a5915dcc20f6 - malicious
- fac8504e0f4e3324b1d48f875ed0822756a2d375c37ac1ab62d23889e8eac352 - malicious
- 02a1bef968a7d64ffd5ace45a9db0854704874349d4d9e5f291ad3a9eae7647d - malicious
Canonical technique definition: MITRE ATT&CK T1059.001 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1059.001
- How common is ATT&CK T1059.001 (PowerShell) in real malware?
- ATT&CK technique T1059.001 PowerShell appears in 413 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.4% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 7 prior). Most associated families: Base64, Avlj, AgentTesla, HUILoader, Lazy.
- Is T1059.001 becoming more common?
- Prevalence is falling: 0 samples in the last seven days against 7 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1059.001?
- In this corpus T1059.001 is most associated with Base64 (21), Avlj (14), AgentTesla (13), HUILoader (11), Lazy (9). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1059.001?
- 0.4% of the publicly analyzed corpus (413 of 114611 samples) exhibits T1059.001. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats