mttaggart / wtfbins

WTF are these binaries doing?! A list of benign applications that mimic malicious behavior.
MIT License
150 stars 12 forks source link

[New WTFBin]: logmein.com #29

Closed joaociocca closed 1 year ago

joaociocca commented 2 years ago

image

image

mttaggart commented 1 year ago

Hmm, I don't know why it would do this, but I don't feel like a program kicking off PowerShell is, by itself, enough to merit a WTFBin. If it were a bizarre domain or base64 encoded, maybe. Even -ep bypass is common enough.

I'm going to pass on this one for now, but I really appreciate the submission! Keep WTFBins in mind in the future!