Wednesday, July 27, 2011

100. Powershell Worm SKOWOR

Name-Worm.MSH.Skowor.A
Type-Worm
Author-sk0r/Czybik
Written in-PowerShell



Description-
I was looking for PowerShell based malware and eventually found the POC Skowor worm. The only worm written in this language.
It attempts to propagate via the Kazaa P2P network by putting a copy of itself in the shared folders. As far as I see there is no typical malicious payload except it overwrites files with a specific file extension.

Good to know it exists and to see how it works.
Download
Source

No comments:

Post a Comment