PowerShell Malware from 147.45.178.149

(topic deleted by author)

@ishaughnessy , appears @pacodiazz deleted?

1 Like

@pacodiazz - Thanks for sharing the payload with us! I got a signature in today’s release based on what you shared, let us know if you find anything else and we’re always happy to take a look!

2066382 - ET ATTACK_RESPONSE Obfuscated PowerShell Payload Inbound

Thanks,
Isaac

1 Like