Unknow Task scheduled that launches powershell with obfuscated command

  • Thread starter Thread starter ~Mohamed~
  • Start date Start date
M

~Mohamed~

Guest
Hello everyone, I've been noticing occasional flashes of the PowerShell window on my computer, which prompted me to investigate further. Upon investigation, I discovered that a PowerShell command is being executed. The command is heavily obfuscated, making it difficult to understand its purpose. Using Procmon.exe, I traced the parent process back to svchost, which seems to be launching the PowerShell instance through scheduled tasks. Although I've checked the Windows Task Scheduler, I couldn't find any suspicious tasks there. However, after looking through the currently running tasks, I identi

Continue reading...
 
Back
Top