101@feddit.org to Technology@lemmy.worldEnglish · 5 days agoBe careful.feddit.orgimagemessage-square163fedilinkarrow-up11arrow-down10file-text
arrow-up11arrow-down1imageBe careful.feddit.org101@feddit.org to Technology@lemmy.worldEnglish · 5 days agomessage-square163fedilinkfile-text
minus-squarex00za@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up0·5 days agoAnybody got more info on the actual payload? powershell.exe -eC [payload_w_base64] is mentioned here. -eC just means encoded command afaik.
minus-squarelooeee@lemmy.worldlinkfedilinkEnglisharrow-up0·5 days agoDeep analysis here https://denwp.com/anatomy-of-a-lumma-stealer
minus-squarex00za@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up0·5 days agoThanks for sharing. I also added that website to my RSS reader.
minus-squarepurplemonkeymad@programming.devlinkfedilinkEnglisharrow-up0·5 days agoSeen this on the powershell subreddit before, it just downloads and runs another executable.
Anybody got more info on the actual payload?
powershell.exe -eC [payload_w_base64]
is mentioned here.-eC
just means encoded command afaik.Deep analysis here https://denwp.com/anatomy-of-a-lumma-stealer
Thanks for sharing.
I also added that website to my RSS reader.
Seen this on the powershell subreddit before, it just downloads and runs another executable.