• XSS.stack #1 – первый литературный журнал от юзеров форума

*HELP* - Infected by Powershell.exe (Clipper/RAT/...)

Looks like you have a rat infestation on your system, abusing lolbins for persistence. I assume "C:\Users\digi-\AppData\Roaming\logs.txt" contains a base64 encoded string.
Have you also installed Sysmon to monitor process execution and other system activities?
 
Hello alotofus here is the file logs.txt but it's crypted :


paste file contents to the input and you will get the decoded form.

In result, this script has ability of replacing clipboard contents with the its operators various (dash, btc, trc20...) cryptocurrency addresses. Additionally operator is able to upload and execute further scripts to the victims machine.
 
I am gonna format and reinstall all my windows... I think it's the best solution ?
Persistence bots if they are well written, it is almost impossible to remove them, trust me, I have been using sality for a few years, and I have tried to remove it from infected computers with any kind of antivirus tool ... ..
 
скачивай тыц запускаешь от Админа, смотришь куда и что ломиться и VT тыц сносишь powershell на х#й, также чистишь все через реестр, но обычно достаточно заменить сам powershell.exe и.т.д
wink.png
 
скачивай тыц запускаешь от Админа, смотришь куда и что ломиться и VT тыц сносишь powershell на х#й, также чистишь все через реестр, но обычно достаточно заменить сам powershell.exe и.т.д
wink.png
Спасибо и удачи в соревнованиях. Закажите свою статью. Я люблю это. Удачи, пойдем за тобой.
 
Output : ÓO@Û`..°Mv(".Ó"rº,¡ûV.whÂÃS×M5÷N6Ð.B<.F<.uè.V.whÂÀÞ}éÝz°M.æ.Ø.N.X§x.M .V.whÂÀÞ}éÝz
You are doing something wrongly. Anyways i've uploaded decoded file (WARNING! MALICIOUS CODE INSIDE),
 

Вложения

  • logs_decoded.txt
    14.2 КБ · Просмотры: 23
Persistence bots if they are well written, it is almost impossible to remove them, trust me, I have been using sality for a few years, and I have tried to remove it from infected computers with any kind of antivirus tool ... ..
wiping disk and reinstalling should remove said malware no?
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх