101@feddit.org to Technology@lemmy.worldEnglish · 2 months agoBe careful.feddit.orgimagemessage-square176fedilinkarrow-up11.65Karrow-down116file-text
arrow-up11.63Karrow-down1imageBe careful.feddit.org101@feddit.org to Technology@lemmy.worldEnglish · 2 months agomessage-square176fedilinkfile-text
minus-squarex00za@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up36·2 months agoAnybody got more info on the actual payload? powershell.exe -eC [payload_w_base64] is mentioned here. -eC just means encoded command afaik.
minus-squarepurplemonkeymad@programming.devlinkfedilinkEnglisharrow-up6·2 months agoSeen this on the powershell subreddit before, it just downloads and runs another executable.
minus-squarelooeee@lemmy.worldlinkfedilinkEnglisharrow-up5·2 months agoDeep analysis here https://denwp.com/anatomy-of-a-lumma-stealer
minus-squarex00za@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up3·2 months agoThanks for sharing. I also added that website to my RSS reader.
Anybody got more info on the actual payload?
powershell.exe -eC [payload_w_base64]
is mentioned here.-eC
just means encoded command afaik.Seen this on the powershell subreddit before, it just downloads and runs another executable.
Deep analysis here https://denwp.com/anatomy-of-a-lumma-stealer
Thanks for sharing.
I also added that website to my RSS reader.
Same