BOOK THIS SPACE FOR AD
ARTICLE AD3. August 2020
Read the original article: Powershell Bot with Multiple C2 Protocols, (Mon, Aug 3rd)
I spotted another interesting Powershell script. It&#x3b;x26x3b;#x3b;39x3b;s a bot and is delivered through a VBA macro that spawns an instance of msbuild.exe This Windows tool is often used to compile/execute malicious on the fly (I already wrote a diary about this techniquex5b;1x5d;). I don't have the original document but based on a technique used in the macro, it is part of a Word document. It calls Documentx5f;ContentControlOnEnterx5b;2x5d;:xd;