Benign powershell Download

PSSailpoint.IaiRecommendations 2.1.40

PowerShell decodes Base64 with ConvertReferences named armored private-key header
SHA-25623bf2eb7403b8d56a0d9253307e0be0c26aa9fdd52fdeeeb92510d86d102fd93
MaleculeTh

Evidence

Authorization header-name literal lines 42–50
42:19… = 'Digest'
43 # The 'Authorization' header is automatically generated by the client. It includes
44 # the list of signed headers and a base64-encoded signature.
45 $HEADER_AUTHORIZATION = 'Authorization'
46
47 #Hash table to store singed headers
48 $HttpSignedRequestHeader = @{ }
49 $HttpSignatureHeader = @{ }
50 $TargetHost = …
Encodes base64 in PowerShell lines 56–59
56:35… HashAlgorithm -eq "SHA256") {
57 $Digest = [String]::Format("SHA-256={0}", [Convert]::ToBase64String($bodyHash))
58 } elseif ($httpSigningConfiguration.HashAlgorithm -eq "SHA512") {
59 $Digest = [String]::Format("SHA-512={ …
References named armored private-key header lines 168–197
168:6…
169 try {
170
171 if ($hashAlgorithmName -eq "sha256") {
172 $hashAlgo = [System.Security.Cryptography.HashAlgorithmName]::SHA256
173 } elseif ($hashAlgorithmName -eq "sha512") {
174 $hashAlgo = [System.Security.Cryptography.HashAlgorithmName]::SHA512
175 }
176
177 if ($PSVersionTable.PSVersion.Major -ge 7) {
178 $ecKeyHeader = "-----BEGIN RSA PRIVATE KEY-----"
179 $ecKeyFooter = "-----END RSA PRIVATE KEY-----"
180 $keyStr = Get-Content -Path $PrivateKeyFilePath -Raw
181 $ecKeyBase64String = $keyStr.Replace($ecKeyHeader, "").Replace($ecKeyFooter, "").Trim()
182 $keyBytes = [System.Convert]::FromBase64String($ecKeyBase64String)
183 $rsa = [System.Security.Cryptography.RSA]::Create()
184 [int]$bytCount = 0
185 $rsa.ImportRSAPrivateKey($keyBytes, [ref] $bytCount)
186
187 if ($SigningAlgorithm -eq "RSASSA-PSS") {
188 $signedBytes = $rsa.SignHash($DataToSign, $hashAlgo, [System.Security.Cryptography.RSASignaturePadding]::Pss)
189 } else {
190 $signedBytes = $rsa.SignHash($DataToSign, $hashAlgo, [System.Security.Cryptography.RSASignaturePadding]::Pkcs1)
191 }
192 } else {
193 $rsa_provider_path = Join-Path -Path $PSScriptRoot -ChildPath "RSAEncryptionProvider.cs"
194 $rsa_provider_sourceCode = Get-Content -Path $rsa_provider_path -Raw
195 Add-Type -TypeDefinition $rsa_provider_sourceCode
196
197 [System.Security.Cryptography.RSA]$rsa = [RSAEncryption.RSAEncryptionProvider]::GetRSAPro …
PowerShell .NET ECDSA object creation lines 250–274
250 $ecKeyFooter = "-----END EC PRIVATE KEY-----"
251 $keyStr = Get-Content -Path $ECKeyFilePath -Raw
252 $ecKeyBase64String = $keyStr.Replace($ecKeyHeader, "").Replace($ecKeyFooter, "").Trim()
253 $keyBytes = [System.Convert]::FromBase64String($ecKeyBase64String)
254 $ecdsa = [System.Security.Cryptography.ECDsa]::Create()
255
256 [int]$bytCount =0
257 if (![string]::IsNullOrEmpty($KeyPassPhrase)) {
258 $ecdsa.ImportEncryptedPkcs8PrivateKey($KeyPassPhrase,$keyBytes,[ref]$bytCount)
259 } else {
260 $ecdsa.ImportPkcs8PrivateKey($keyBytes,[ref]$bytCount)
261 }
262
263 $signedBytes = $ecdsa.SignHash($DataToSign)
264 $derBytes = ConvertTo-ECDSAANS1Format -RawBytes $signedBytes
265 $signedString = [System.Convert]::ToBase64String($derBytes)
266 return $signedString
267}
⋯7 lines
PowerShell .NET ComputeHash call lines 291–301
291:40… ryptography.HashAlgorithm]::Create($HashName)
292 $hashAlgorithm.ComputeHash([System.Text.Encoding]::UTF8.GetBytes($String))
293}
294
⋯7 lines

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.