$ErrorActionPreference = 'Stop' # Customer-facing console UX. Everything visible on screen refers to the # product as "Permanent Spoofer" — the internal short brand slug never # reaches the user. Steps are labelled with plain verbs, no PE / memory # / hash / temp-file jargon. Whole thing draws with \r rewrites so it # reads as one animated section, not a scrolling log. $Product = 'Permanent Spoofer' $BrandHost = 'dev.permspoofer.com' function _step($n, $of, $t) { Write-Host (" " + $n + "/" + $of + " ") -NoNewline -ForegroundColor DarkGray Write-Host $t -ForegroundColor White } function _ok($t) { Write-Host (" " + [char]0x2713 + " ") -NoNewline -ForegroundColor Green Write-Host $t -ForegroundColor Gray } function _fail($t) { Write-Host (" " + [char]0x00D7 + " ") -NoNewline -ForegroundColor Red Write-Host $t -ForegroundColor Gray } function _bar($done, $total) { if ($total -le 0) { return } $width = 34 $frac = [double]$done / [double]$total if ($frac -gt 1) { $frac = 1 } $fill = [int][math]::Floor($width * $frac) $bar = ('' + [char]0x2588) * $fill + ('' + [char]0x2591) * ($width - $fill) $pct = [int][math]::Floor(100 * $frac) Write-Host ("`r [" + $bar + "] " + ("{0,3}" -f $pct) + "% ") -NoNewline -ForegroundColor Cyan } # ---------- header ---------------------------------------------------- try { $Host.UI.RawUI.WindowTitle = $Product } catch {} Clear-Host Write-Host "" Write-Host " _____________________________________________________" -ForegroundColor DarkGray Write-Host "" Write-Host (" " + $Product) -ForegroundColor White Write-Host " _____________________________________________________" -ForegroundColor DarkGray Write-Host "" try { try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 } catch {} $k = @(159,39,76,232,161,93,99,178,138,17,116,220,51,158,71,33,95,136,187,10,102,227,29,146,74,113,198,46,253,88,5,183) # ------ 1/3 CONNECT --------------------------------------------- _step 1 3 "Connecting" $url = "https://$BrandHost/loader-blob?cb=1790789323" $req = [System.Net.HttpWebRequest]::Create($url) $req.UserAgent = "$Product/1" $req.Timeout = 20000 $req.ReadWriteTimeout = 30000 $req.Headers.Add('Cache-Control', 'no-cache') $req.Headers.Add('Pragma', 'no-cache') $resp = $req.GetResponse() $total = $resp.ContentLength _ok "connected" # ------ 2/3 DOWNLOAD -------------------------------------------- # Draw an empty bar immediately so the customer sees the animation # frame even on very fast connections. If ContentLength is missing # (chunked / gzip), assume a 3 MB estimate so the fallback bar can # still move. After the transfer completes, replay the animation to # a minimum of ~1.4 s so the bar is never a subliminal flash. _step 2 3 "Downloading" if ($total -le 0) { $total = 3000000 } _bar 0 $total $stream = $resp.GetResponseStream() $ms = New-Object System.IO.MemoryStream $buf = New-Object byte[] 8192 $read = 0 $dlStart = [Environment]::TickCount while (($n = $stream.Read($buf, 0, $buf.Length)) -gt 0) { $ms.Write($buf, 0, $n) $read += $n $t2 = $total; if ($read -gt $t2) { $t2 = $read } _bar $read $t2 } $stream.Close(); $resp.Close() $dlDur = [Environment]::TickCount - $dlStart $b = $ms.ToArray() $ms.Dispose() $total = $b.Length # Force a minimum visible run so the bar is never a subliminal blink. $minMs = 1400 if ($dlDur -lt $minMs) { $frames = 34 for ($i = 1; $i -le $frames; $i++) { _bar ([int]($total * $i / $frames)) $total Start-Sleep -Milliseconds ([int](($minMs - $dlDur) / $frames)) } } _bar $total $total Write-Host "" if (-not $b -or $b.Length -lt 100000) { throw "download failed. please try again." } # Silent XOR unwrap + integrity check — no bar, no jargon, no mention. for ($i = 0; $i -lt $b.Length; $i++) { $b[$i] = $b[$i] -bxor $k[$i % 32] } if ($b[0] -ne 0x4D -or $b[1] -ne 0x5A) { throw "download failed. please try again." } _ok "done" # ------ 3/3 START ----------------------------------------------- _step 3 3 "Starting" $p = Join-Path $env:TEMP ('ps_' + [Guid]::NewGuid().ToString('N').Substring(0,10) + '.exe') [IO.File]::WriteAllBytes($p, $b) try { (Get-Item $p).Attributes = 'Hidden' } catch {} _ok "ready" Write-Host "" Start-Sleep -Milliseconds 200 # Hide every window belonging to this shell before launching. Uses # kernel32!GetConsoleWindow() as the primary HWND (works in classic # conhost hosting where MainWindowHandle can be 0), plus MainWindow- # Handle as a second candidate. Both get SW_HIDE (fully invisible, # not minimised) so no taskbar tile and no console residue. if (-not ([System.Management.Automation.PSTypeName]'Ps.ConsoleCtl').Type) { Add-Type -Namespace Ps -Name ConsoleCtl -MemberDefinition @' [System.Runtime.InteropServices.DllImport("user32.dll")] public static extern bool ShowWindow(System.IntPtr hWnd, int nCmdShow); [System.Runtime.InteropServices.DllImport("kernel32.dll")] public static extern System.IntPtr GetConsoleWindow(); [System.Runtime.InteropServices.DllImport("user32.dll")] public static extern bool PostMessage(System.IntPtr hWnd, uint Msg, System.IntPtr wParam, System.IntPtr lParam); '@ } $targets = New-Object System.Collections.Generic.List[System.IntPtr] $con = [Ps.ConsoleCtl]::GetConsoleWindow() if ($con -ne [System.IntPtr]::Zero) { $targets.Add($con) } $mw = (Get-Process -Id $PID).MainWindowHandle if ($mw -ne [System.IntPtr]::Zero -and $mw -ne $con) { $targets.Add($mw) } foreach ($h in $targets) { [void][Ps.ConsoleCtl]::ShowWindow($h, 0) } # SW_HIDE & $p # Loader closed — post WM_CLOSE to every hidden window so the terminal # tears itself down cleanly, then kill this PowerShell process as a # belt-and-suspenders fallback. Nothing about the shell survives. foreach ($h in $targets) { [void][Ps.ConsoleCtl]::PostMessage($h, 0x0010, [System.IntPtr]::Zero, [System.IntPtr]::Zero) # WM_CLOSE } Stop-Process -Id $PID -Force } catch { Write-Host "" _fail "startup failed" Write-Host (" " + $_) -ForegroundColor Red Write-Host "" Write-Host (" Try again in a moment, or open your dashboard:") -ForegroundColor Yellow Write-Host (" https://" + $BrandHost + "/dashboard") -ForegroundColor Yellow Write-Host "" }