enotkrutoy commited on
Commit
084a764
·
verified ·
1 Parent(s): fd4014e

Rename test/calc to test/payload

Browse files
Files changed (2) hide show
  1. test/calc +0 -1
  2. test/payload +5 -0
test/calc DELETED
@@ -1 +0,0 @@
1
- Invoke-Item c:\windows\system32\calc.exe
 
 
test/payload ADDED
@@ -0,0 +1,5 @@
 
 
 
 
 
 
1
+ #Invoke-Item c:\windows\system32\calc.exe
2
+ $payloadParameters = "start-process calc.exe";
3
+ $encodedPayload = [System.Convert]::ToBase64String([System.Text.Encoding]::Unicode.GetBytes($payloadParameters));
4
+ $payload = "powershell.exe -ep Bypass -noexit -enc $encodedPayload"
5
+ $payload|IEX;