The .cmd extension concealed the underlying PowerShell content. I exposed its structure by reformatting the code and renaming variables, then changed the execution function to print decoded commands. This revealed how the loader retrieved its next stage.
Viewed
Growing MSSP with Offensive Services
Decoding the first stage
From obfuscated PowerShell to MSBuild injection
Return to the full story ←