filmov
tv
Analyzing PowerShell Payloads - Part 5
Показать описание
Example 5: PowerShell payload containing shellcode contained within obfuscated hexadecimal data
Cyber Chef Recipe
Regular_expression('User defined','[0-9a-zA-Z+/=]{30,}',true,true,false,false,false,false,'List matches')
From_Base64('A-Za-z0-9+/=',true)
Remove_null_bytes()
Regular_expression('User defined','[0-9a-z\\<\\,]{30,}',true,true,false,false,false,false,'List matches')
Find_/_Replace({'option':'Regex','string':'<'},'BxDx',true,false,true,false)
Find_/_Replace({'option':'Regex','string':'BxD'},'0',true,false,true,false)
From_Hex('Auto')
--
John Dwyer
--
Disclaimer: Samples shown in the video were pulled from open source intel locations and we don't recommend accessing the associated IPs or domains.
Cyber Chef Recipe
Regular_expression('User defined','[0-9a-zA-Z+/=]{30,}',true,true,false,false,false,false,'List matches')
From_Base64('A-Za-z0-9+/=',true)
Remove_null_bytes()
Regular_expression('User defined','[0-9a-z\\<\\,]{30,}',true,true,false,false,false,false,'List matches')
Find_/_Replace({'option':'Regex','string':'<'},'BxDx',true,false,true,false)
Find_/_Replace({'option':'Regex','string':'BxD'},'0',true,false,true,false)
From_Hex('Auto')
--
John Dwyer
--
Disclaimer: Samples shown in the video were pulled from open source intel locations and we don't recommend accessing the associated IPs or domains.
Analyzing PowerShell Payloads - Part 1
Analyzing PowerShell Payloads Part 1
Analyzing PowerShell Payloads - Part 3
Analyzing PowerShell Payloads - Part 2
Analyzing PowerShell Payloads - Part 5
Analyzing PowerShell Payloads - Part 6
Analyzing PowerShell Payloads Part 2
Analyzing PowerShell Payloads Part 3
Analyzing PowerShell Payloads - Part 7
Analyzing PowerShell Payloads - Part 4
Analyzing PowerShell Payloads EP9
Analyzing PowerShell Payloads Part 6
Analyzing PowerShell Payloads Part 5
Analyzing PowerShell Payloads Part 4
Analyzing PowerShell Payloads Part 7
Analyzing PowerShell Payloads Episode 10
Analyzing PowerShell payloads - Episode 8
Analyzing PowerShell Payloads - Episode 11
BTLO Malicious PowerShell Analysis Walkthru
Fileless Malware Analysis & PowerShell Deobfuscation
Learn Polymorphic Powershell Payload Techniques! [PAYLOAD]
Malicious PowerShell Execution Techniques
NEW Powershell features in DuckyScript 3.0
Finding and Decoding Malicious Powershell Scripts - SANS DFIR Summit 2018
Комментарии