John Lambert Profile picture
Corporate Vice President, Security Fellow, Microsoft Security Research, johnla(AT)https://t.co/3dGtq71Nby

Dec 23, 2016, 12 tweets

If you are looking to study #PowerShell #malware for #DFIR a roundup follows

1,300 line #PowerShell Trojan: , pastebin.com/nhtVrdgs

1200 line obfuscated payload dropped by Word macro: , pastebin.com/V1F1hRg7

Some #PowerShell payloads I’ve seen in the wild: pastebin.com/juC4CkQG and pastebin.com/R75bqYkL

#Powershell threat targeting Brazil: , pastebin.com/KiWD1juJ

Some common #PowerShell download & run methods:

#PowerShell malware stealing credentials: , pastebin.com/R8wqMKYP

#PowerShell Obfuscation talk by @danielhbohannon: ,

#DFIR Python tool to decode common encoded #PowerShell malware, PsXray:

Defending against malicious #PowerShell by @PyroTek3: adsecurity.org/wp-content/upl…

Symantec report on #PowerShell malware: symantec.com/content/dam/sy…

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling