Concerned About Your Business Cyber Security?

(877) 321--7374

Malicious Powershell using a Decoy Picture, (Mon, Oct 22nd)

I found another interesting piece of malicious Powershell while hunting. The file size is 1.3MB and most of the file is a PE file Base64 encoded. You can immediately detect it by checking the first characters of the string:

Ready For ASuperheroI.T. Solution?

Real Time Web Analytics