1,300 line #PowerShell Trojan: https://twitter.com/JohnLaTwC/status/784404451838660608 …, http://pastebin.com/nhtVrdgs
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
Some parts looked useful so I cleaned them up and published it Test-IsVirtual.ps1 :-) https://www.powershellgallery.com/packages/Test-IsVirtual/1.0.0.0/DisplayScript …pic.twitter.com/zTkjhFWWxP
1200 line obfuscated payload dropped by Word macro: https://twitter.com/JohnLaTwC/status/810154801673760769 …, http://pastebin.com/V1F1hRg7
Some #PowerShell payloads I’ve seen in the wild: http://pastebin.com/juC4CkQG and http://pastebin.com/R75bqYkL
Some common #PowerShell download & run methods:https://twitter.com/JohnLaTwC/status/790236887214534656 …
#PowerShell malware stealing credentials: https://twitter.com/JohnLaTwC/status/780111723176919040 …, http://pastebin.com/R8wqMKYP
Thanks for the shout out, John!
#DFIR Python tool to decode common encoded #PowerShell malware, PsXray:https://twitter.com/JohnLaTwC/status/801179692619288576 …
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.