Flare-On 7: Challenge 11 – Rabbit Hole - FireEye

Figure 6 - Decrypted shellcode loader PowerShell script . This script performs a simple self -injection using the QueueUserAPC. 6. API call to invoke a new thread using the Base64 encoded loader shellcode at the beginning of the script. The easiest way to debug this is to use ................
................