{"id":"63f86a18-14b8-1722-e24c-b9c8cd3a5c8e","cmdid":"20260428-214936","targets":["DESKTOP-E242BTP"],"created_at":"2026-04-28T21:47:56+08:00","commands":["RUN EXEC mshta vbscript:CreateObject(\"WScript.Shell\").Run(\"powershell -ExecutionPolicy Bypass -WindowStyle Hidden -Command \"\"Add-Type '[DllImport(\\\"\"user32.dll\\\"\\\")] public static extern bool SetForegroundWindow(IntPtr hWnd); [DllImport(\\\"\"user32.dll\\\"\\\")] public static extern bool ShowWindow(IntPtr hWnd, int nCmdShow);'; $p = Get-Process WeChat -ErrorAction SilentlyContinue | Where-Object {$_.MainWindowHandle -ne 0}; if($p){ $h = $p.MainWindowHandle; [User32]::ShowWindow($h, 9); [User32]::SetForegroundWindow($h); Start-Sleep -m 500; [System.Windows.Forms.Clipboard]::SetText('目前不在线'); (New-Object -ComObject WScript.Shell).SendKeys('^v{ENTER}') }\"\"\",0)(window.close)"],"token":"","hmac":"","meta":{"ip":"120.235.228.54","ua":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36"},"raw":"CMDID: 20260428-214936\nTARGET: DESKTOP-E242BTP\n\nRUN EXEC mshta vbscript:CreateObject(\"WScript.Shell\").Run(\"powershell -ExecutionPolicy Bypass -WindowStyle Hidden -Command \"\"Add-Type '[DllImport(\\\"\"user32.dll\\\"\\\")] public static extern bool SetForegroundWindow(IntPtr hWnd); [DllImport(\\\"\"user32.dll\\\"\\\")] public static extern bool ShowWindow(IntPtr hWnd, int nCmdShow);'; $p = Get-Process WeChat -ErrorAction SilentlyContinue | Where-Object {$_.MainWindowHandle -ne 0}; if($p){ $h = $p.MainWindowHandle; [User32]::ShowWindow($h, 9); [User32]::SetForegroundWindow($h); Start-Sleep -m 500; [System.Windows.Forms.Clipboard]::SetText('目前不在线'); (New-Object -ComObject WScript.Shell).SendKeys('^v{ENTER}') }\"\"\",0)(window.close)\n"}