Post B4bA7X6AUE8KfuYScC by pwloftus@pwl.farted.net
(DIR) More posts by pwloftus@pwl.farted.net
(DIR) Post #B4b9rP6yPkaxGpEz2G by pwloftus@pwl.farted.net
0 likes, 0 repeats
@staff @stux @mike There is an account on each of your servers @ DemLabs that is linking users to a fake Cloudflare verification page that is hosting a trojan / malicious obfuscated powershell script.It creates a directory, downloads an executable, runs the executable and checks from the browser to see that it's there. If the executable runs the script finishes by cleaning up after itself.The executable reads and edits several windows registry keys.
(DIR) Post #B4b9rPLVXiDlzu2agq by stux@mstdn.social
0 likes, 0 repeats
@pwloftus @staff @mike Thank you! Solved!
(DIR) Post #B4bA7X6AUE8KfuYScC by pwloftus@pwl.farted.net
0 likes, 0 repeats
@stux @staff @mike you’re welcome. Have a great day!