I’ve seen the same method once in a PowerShell hacktool that had an EICAR string in a comment right at the beginning of the file - my guess was that the attacker wasn’t sure about the AV excluded Dir on a remote host
Today’s breach is brought to you by British Airways. Read between the lines: perhaps the financial data was unencrypted or someone harvested it at entry. If you’re affected talk to your bank &/or card issuer straight away.
My favourite is the Group Policy Preferences file, because you literally need nothing (but a domain joined system) to exploit them
You can use my CyberChef recipe to decode the encrypted password with any browser
https://t.co/5qhi6TwSuy
@lecanardnoir @pandocruises I wonder if @pandocruises get a pass because they are operating in International waters? Because they do seem to advertise various forms of quackery and claim efficacy for serious illnesses in their onboard literature.
@ViktoriaCsendes@SidAlpha@whatever541 Sometimes it just seems to be a case of throwing whatever slurs they can think of at you, in the hope that some might stick.