Undetected PowerShell Backdoor Disguised as a Profile File, (Fri, Jun 9th)

PowerShell remains an excellent way to compromise computers. Many PowerShell scripts found in the wild are usually obfuscated. Most of the time, this helps to have the script detected by fewer antivirus vendors. Yesterday, I found a script that scored 0/59 on VT! Let’s have a look at it.

Continue reading Undetected PowerShell Backdoor Disguised as a Profile File, (Fri, Jun 9th)→

Posted in Uncategorized

Ongoing scans for Geoserver, (Thu, Jun 8th)

Looking at today&#;x26;#;39;s weblogs from our honeypot, I noticed one IP in particular, %%ip:83.97.73.89%%, scanning for “/geoserver” related URLs. This isn&#;x26;#;39;t new, and we have seen researchers, in particular Shadowserver, looking for similar URLs at least since the beginning of the year.

Continue reading Ongoing scans for Geoserver, (Thu, Jun 8th)→

Posted in Uncategorized