This LoadPE shellcode
- Support TLS
- Don`t need relocation table
For using it you must to create next data structure:
For using this shellcode you must patch it
Main file - loadpe.asm
Plugin for unchain SEH with restore original (system) handler exception and restore stack to original state (it can be changed by RTL start code)
Plagin for EOF (overlay) simulation for Сitadel і Zeus.
Attached Files
Edited by 0xDADA11C7, 28 December 2014 - 11:29 PM.