- Oct 13, 2019
- 784
Yeah I’m curious what that sample does. DeepGuard flagged it as a PowerShell stager which makes me suspect it isn’t the batch file doing the dirty deed, it’s something it launched which DeepGuard knew how to monitor. The pathway from BAT -> EXE which is trusted but generic (like regedit, net, taskkill, etc) seems to be the big weakness.I also got the feeling that for example malicious BAT files detection is something that needs to be improved, but 100% totally blind I can't say because F-Secure does actually from time to time catch even those as clearly can be seen here: