
Executable’s batch file launched multiple PowerShell script requests
An executable invoked a temporary batch file whose PowerShell children named several remote scripts. A separately analyzed shortcut ran the same command for one script URL and produced a DNS lookup, but the records do not show that the executable launched that shortcut.
A Windows executable launched a temporary batch file whose child PowerShell processes named several remote script URLs. In a separate analysis, a Windows shortcut launched the same PowerShell command aimed at one of those URLs, http://marketprice.pk/zxcvb.ps1, and its sandbox recorded a DNS lookup for the domain. What connects the two files: a direct handoff, or a shared way of retrieving and executing code?
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read