Files
sigma-rules/rta/bin/PsRunner.exe
T

75 lines
7.5 KiB
Plaintext
Raw Normal View History

2020-06-29 23:07:16 -06:00
MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode.
$PEL:ñ»Yà" 0š2 @@ @…H2O@¬` 1  H.text   `.rsrc¬@@@.reloc `@B|2HD"Ì0}(
o
s
&o
%o
o
%o
rpo
o
o
s
o
+o
 o
&o
-éÞ
,o
Üo
o
*Lg
.rp(
*0Ži.p(!
(*š š p("
,(#
ݸ&rÞp(!

ݶrp("
,#s$
o%
݈&rp(!

݆r@p("
,8(&
o'
o(
(#
%¢o)
š
Þ@&rFp(!

ÞAr~p("
,
Þ &r„p(!

Þ!r´p(!
(*, ((
* *4, 8WhÌÐ(*
*BSJB v4.0.30319l(#~¤#Strings8è#US
#GUID0
œ#BlobG ú3"*[п=¿Yß,ô³ôô$ôðô ôCô ö wô^h-Á
ny"n>
+×
y
w×
Ùy
yš9óÁÁÁ%E4#Y®YÁ¹0AP /ƒì µø Ò¹<"S]î SSS
)S1S9SASISQSYSaSiSqSyS©h)ͱS.Ó4¹l9Á[ÁY¹>âS ENO^acÑeiÙèmáÈméðqéÉqá}ñzƒùSùˆŸ ¼má?S. ¿.È.ç.#ð.+þ.3þ.;þ.Cð.K.Sþ.[þ.c.kF.sSvGW0£5¬×£ÁCollection`1IEnumerator`1<Module>System.IORunPSmscorlibSystem.Collections.GenericAddcmdAppendCreateRunspaceRunspaceInvokeIDisposableFileConsoleget_MainModuleProcessModuleget_FileNameWriteLineCreatePipelineCloseDisposeWriteGuidAttributeDebuggableAttributeComVisibleAttributeAssemblyTitleAttributeAssemblyTrademarkAttributeTargetFrameworkAttributeAssemblyFileVersionAttributeAssemblyConfigurationAttributeAssemblyDescriptionAttributeCompilationRelaxationsAttributeAssemblyProductAttributeAssemblyCopyrightAttributeAssemblyCompanyAttributeRuntimeCompatibilityAttributePsRunner.exeSystem.Runtime.VersioningDownloadStringToStringSystem.Collections.ObjectModelProgramSystemTrimOpenMainSystem.Management.AutomationSystem.ReflectionCommandCollectionPrintHelpStringBuilderPsRunnerIEnumeratorGetEnumerator.ctorSystem.Diagnosticsget_CommandsSystem.Management.Automation.RunspacesSystem.Runtime.InteropServicesSystem.Runtime.CompilerServicesDebuggingModesargsSystem.CollectionsStringSplitOptionsGetCurrentProcessPSObjectSystem.NetSplitWebClientget_CurrentAddScriptMoveNextSystem.TextReadAllTextRunspaceFactoryop_EqualityOut-StringƒuInexorablePoSH
Workaround for AppLocker deny of Powershell using .NET
inexorableposh.exe [<flag> <argument>]
flags:
-f <file> : Read script from specified file
-r <resource name> : Read script from specified resource
-d <url> : Read script from URL
-a <delimeter> : Read script appended to current binary after specified delimeter. Delimeter should be very very unique string
-c <command> : PowerShell command to execute, enclosed on quotes.I[!] Error: Proper arguments required-f)[!] Error: File Fail-d1[!] Error: Download Fail-a7[!] Error: Append Read fail-c/[!] Error: Command fail1[!] Error: Improper flag]#·¬ù·ºFžŠE½ÀÂ@ô     EIMQQE E ] a eQeQ MMQ  I    €… €‰·z\V4à‰1¿8V­6N5TWrapNonExceptionThrows
PsRunnerCopyright © 2017)$83775b1c-2c73-4023-a00c-8bc0ca080cda 1.0.0.0G.NETFramework,Version=v4.0TFrameworkDisplayName.NET Framework 4:ñ»Y,1,RSDS$3Oܽ¼K´’“JcŒå)C:\GIT\rta\red_ttp\myapp\PsRunner\obj\Release\PsRunner.pdbp2Š2 |2_CorExeMainmscoree.dllÿ% @ P8h¬@4VS_VERSION_INFO½ïþ?DVarFileInfo$Translation°|StringFileInfoX000004b0Comments"CompanyName: FileDescriptionPsRunner0FileVersion1.0.0.0:
InternalNamePsRunner.exeHLegalCopyrightCopyright © 2017*LegalTrademarksB
OriginalFilenamePsRunner.exe2 ProductNamePsRunner4ProductVersion1.0.0.08Assembly Version1.0.0.0¼Cê<?xml version="1.0" encoding="UTF-8" standalone="yes"?>