[DiscordArchive] what's the point of the whole thing then?
[DiscordArchive] what's the point of the whole thing then?
Archived author: Warpten • Posted: 2018-10-06T13:08:14.369000+00:00
Original source
also runs as admin
Archived author: Warpten • Posted: 2018-10-06T13:08:16.868000+00:00
Original source
¯\_(ツ)_/¯
Archived author: Skarn • Posted: 2018-10-06T13:08:30.991000+00:00
Original source
it is nice not to be on windows most of the time
Archived author: Warpten • Posted: 2018-10-06T13:08:31.837000+00:00
Original source
f ([UACTokenMagic]::CreateProcessWithLogonW("aaa", "bbb", "ccc", 0x00000002, $BinPath, $Args, 0x04000000, $null, $CurrentDirectory,[ref]$StartupInfo, [ref]$ProcessInfo))
Archived author: Warpten • Posted: 2018-10-06T13:08:40.948000+00:00
Original source
aaa bbb ccc are dummies, resp user, domain, password
Archived author: Skarn • Posted: 2018-10-06T13:08:50.593000+00:00
Original source
yeah
Archived author: Warpten • Posted: 2018-10-06T13:08:52.169000+00:00
Original source
the downloaded exe probably sets up some admin account domain wide
Archived author: Warpten • Posted: 2018-10-06T13:08:58.777000+00:00
Original source
and then uses that
Archived author: Skarn • Posted: 2018-10-06T13:09:06.246000+00:00
Original source
most likely locks your system
Archived author: Skarn • Posted: 2018-10-06T13:09:09.177000+00:00
Original source
and encrypts files