{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:36SHMC57NOSCI6OV7XWWYBRCTS","short_pith_number":"pith:36SHMC57","schema_version":"1.0","canonical_sha256":"dfa4760bbf6ba42479d5fded6c06229ca00cfd9bf1b8c2bd3a05a3126638054e","source":{"kind":"arxiv","id":"2401.07995","version":2},"attestation_state":"computed","paper":{"title":"The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Eva Ruhsar Varlioglu, Murat Ozer, Nelly Elsayed, Said Varlioglu, Zag ElSayed","submitted_at":"2024-01-15T22:36:56Z","abstract_excerpt":"Fileless malware predominantly relies on PowerShell scripts, leveraging the native capabilities of Windows systems to execute stealthy attacks that leave no traces on the victim's system. The effectiveness of the fileless method lies in its ability to remain operational on victim endpoints through memory execution, even if the attacks are detected, and the original malicious scripts are removed. Threat actors have increasingly utilized this technique, particularly since 2017, to conduct cryptojacking attacks. With the emergence of new Remote Code Execution (RCE) vulnerabilities in ubiquitous l"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2401.07995","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-01-15T22:36:56Z","cross_cats_sorted":[],"title_canon_sha256":"5dbc8381aec4a8282c6ae12d3bfed27bb007084a10259e4d4b41dccaf1db670d","abstract_canon_sha256":"38390a565c227a903d81364369b7ddfd9b5260434c7bd19445166f56bc44ceef"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:47:46.457365Z","signature_b64":"OgPlyXT4l4pm7KyFNbUC2da7kws2CPhUqFaZ3wR3NLvKl9zGhqG/Va4XjMg4pLcw/1eMGVQACSevDJW0MsWaBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dfa4760bbf6ba42479d5fded6c06229ca00cfd9bf1b8c2bd3a05a3126638054e","last_reissued_at":"2026-07-05T07:47:46.456849Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:47:46.456849Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Eva Ruhsar Varlioglu, Murat Ozer, Nelly Elsayed, Said Varlioglu, Zag ElSayed","submitted_at":"2024-01-15T22:36:56Z","abstract_excerpt":"Fileless malware predominantly relies on PowerShell scripts, leveraging the native capabilities of Windows systems to execute stealthy attacks that leave no traces on the victim's system. The effectiveness of the fileless method lies in its ability to remain operational on victim endpoints through memory execution, even if the attacks are detected, and the original malicious scripts are removed. Threat actors have increasingly utilized this technique, particularly since 2017, to conduct cryptojacking attacks. With the emergence of new Remote Code Execution (RCE) vulnerabilities in ubiquitous l"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2401.07995","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2401.07995/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2401.07995","created_at":"2026-07-05T07:47:46.456920+00:00"},{"alias_kind":"arxiv_version","alias_value":"2401.07995v2","created_at":"2026-07-05T07:47:46.456920+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2401.07995","created_at":"2026-07-05T07:47:46.456920+00:00"},{"alias_kind":"pith_short_12","alias_value":"36SHMC57NOSC","created_at":"2026-07-05T07:47:46.456920+00:00"},{"alias_kind":"pith_short_16","alias_value":"36SHMC57NOSCI6OV","created_at":"2026-07-05T07:47:46.456920+00:00"},{"alias_kind":"pith_short_8","alias_value":"36SHMC57","created_at":"2026-07-05T07:47:46.456920+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.09308","citing_title":"Quantum Algorithm Software for Condensed Matter Physics","ref_index":157,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS","json":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS.json","graph_json":"https://pith.science/api/pith-number/36SHMC57NOSCI6OV7XWWYBRCTS/graph.json","events_json":"https://pith.science/api/pith-number/36SHMC57NOSCI6OV7XWWYBRCTS/events.json","paper":"https://pith.science/paper/36SHMC57"},"agent_actions":{"view_html":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS","download_json":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS.json","view_paper":"https://pith.science/paper/36SHMC57","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2401.07995&json=true","fetch_graph":"https://pith.science/api/pith-number/36SHMC57NOSCI6OV7XWWYBRCTS/graph.json","fetch_events":"https://pith.science/api/pith-number/36SHMC57NOSCI6OV7XWWYBRCTS/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS/action/timestamp_anchor","attest_storage":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS/action/storage_attestation","attest_author":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS/action/author_attestation","sign_citation":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS/action/citation_signature","submit_replication":"https://pith.science/pith/36SHMC57NOSCI6OV7XWWYBRCTS/action/replication_record"}},"created_at":"2026-07-05T07:47:46.456920+00:00","updated_at":"2026-07-05T07:47:46.456920+00:00"}