❌

Normal view

Received yesterday β€” 9 August 2026 ⏭ /r/netsec - Information Security News & Discussion

Analyzing a Multi-Stage PowerShell Payload Chain

I recently analyzed a multi-stage PowerShell payload delivery chain involving heavily obfuscated PowerShell loaders and remotely hosted payloads.

The analysis covers PowerShell deobfuscation, hidden execution, Base64/XOR decoding, a decoy β€œVerification complete!” prompt, payload delivery, and IOCs.

Initial indicators:

203[.]188[.]171[.]166
dorenzaa[.]com

submitted by /u/anuraggawande
[link] [comments]
Received β€” 25 June 2026 ⏭ /r/netsec - Information Security News & Discussion

Researcher accidentally gained access to a threat actor-controlled phishing website

An interesting write-up from https://x.com/unrequitedlyfe describing how an accidental login led to access to a threat actor-controlled phishing website.

The blog provides a behind-the-scenes look at phishing infrastructure, operational mistakes made by the actor, backend panels, and infrastructure pivoting opportunities that can assist threat intelligence investigations.

Worth a read for those interested in phishing analysis, OSINT, and threat actor infrastructure tracking.

submitted by /u/anuraggawande
[link] [comments]
❌