Jump to content

Starting up my Malwarebytes i saw it blocking powershell id'ing commands.

Stuff like this 

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 10/1/23
Protection Event Time: 4:49 PM
Log File: c26a74c2-6069-11ee-a04d-d8bbc19dc8ff.json

-Software Information-
Version: 4.6.2.281
Components Version: 1.0.2131
Update Package Version: 1.0.75853
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3448)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadProcessBlock, C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell $env:firmware_type, Blocked, 701, 392684, 0.0.0, , 

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload process blocked
File Name: C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell $env:firmware_type
URL: 



(end)
Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 10/1/23
Protection Event Time: 4:49 PM
Log File: c2719bee-6069-11ee-a9cb-d8bbc19dc8ff.json

-Software Information-
Version: 4.6.2.281
Components Version: 1.0.2131
Update Package Version: 1.0.75853
License: Premium

-System Information-
OS: Windows 10 (Build 19045.3448)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Exploit.PayloadProcessBlock, C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell Confirm-SecureBootUEFI, Blocked, 701, 392684, 0.0.0, , 

-Exploit Data-
Affected Application: cmd
Protection Layer: Application Behavior Protection
Protection Technique: Exploit payload process blocked
File Name: C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe powershell Confirm-SecureBootUEFI
URL: 



(end)

So im thinking maybe this is a payload from a malware. Doing a scan finds nothing 

Link to comment
https://linustechtips.com/topic/1533860-am-i-infected/
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×