Powershell Bot with Multiple C2 Protocols, (Mon, Aug 3rd)

3 years ago 132
BOOK THIS SPACE FOR AD
ARTICLE AD

3. August 2020

Read the original article: Powershell Bot with Multiple C2 Protocols, (Mon, Aug 3rd)


I spotted another interesting Powershell script. It&&#x23x3b;x26x3b;&#x23x3b;39x3b;s a bot and is delivered through a VBA macro that spawns an instance of msbuild.exe This Windows tool is often used to compile/execute malicious on the fly (I already wrote a diary about this techniquex5b;1x5d;). I don&#x27t have the original document but based on a technique used in the macro, it is part of a Word document. It calls Documentx5f;ContentControlOnEnterx5b;2x5d;:xd;


Read the original article: Powershell Bot with Multiple C2 Protocols, (Mon, Aug 3rd)

Read Entire Article