It's quite possible those are just loaders, or maybe they have good sandbox detection built-in. I did not investigate any further myself.
By the way, after deobfuscating the popup generation script, it seems it has been created with use of chatgpt/other AI tool and even includes comments like:
是那个ps1后缀的文件吗?
这是上了什么黄网
@fdiskmbr #221 不是,这是直接从那条命令解析出来的网址里获取的恶意脚本,应该只是第一阶段的行动(作用是在ProgramData下放置脚本和添加任务计划),所以没有查出来行为异常。它在你电脑生成的那个文件才是第二阶段攻击的恶意脚本。
太狠了
@frontecho #219
It's quite possible those are just loaders, or maybe they have good sandbox detection built-in. I did not investigate any further myself.
By the way, after deobfuscating the popup generation script, it seems it has been created with use of chatgpt/other AI tool and even includes comments like:
这些很可能只是加载器,或者它们内置了强大的沙盒检测机制。我自己没有进一步深入研究。
顺便说一句,在对弹出窗口生成脚本进行去混淆后,发现它似乎是用ChatGPT或其他AI工具生成的,甚至包含类似这样的注释:
等我装完系统,就把这个文件,上传沙箱读取一下!太他妈狡猾了!
真实文件是这个!
网上冲浪,安全第一
学到了。如果是我可能真会试试执行
笑死我了