Scans Attempting to use PowerShell to Download PHP Script

Published: 2018-05-06
Last Updated: 2018-05-07 01:08:59 UTC
by Guy Bruneau (Version: 1)
4 comment(s)

A few days ago I started seeing in my honeypot traffic attempting to use PowerShell to download a php script as a test. The script might look like this.

Using Cyberchef, I decoder the base64 URL but the php script was no longer available.

Have you seen a similar query in your logs? We would be interested in getting a copy of the php script.You can use our contact page to submit a copy.



Guy Bruneau IPSS Inc.
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu

Keywords: PHP PowerShell Scans
4 comment(s)


Diary Archives