XR3X
Clicky

Jump to content


Photo

[FASM] x86 LoadPE shellcode with plugin support

source

  • You cannot start a new topic
  • Please log in to reply
2 replies to this topic

#1 0xDADA11C7

0xDADA11C7

    Beginner

  • Members +
  • 12 posts
  • LocationUkraine

Posted 28 December 2014 - 11:19 PM

This LoadPE shellcode

  • Support TLS
  • Don`t need relocation table

For using it you must to create next data structure:
 

Please Login or Register to see this Hidden Content

For using this shellcode you must patch it

Please Login or Register to see this Hidden Content

Main file - loadpe.asm

Please Login or Register to see this Hidden Content

Plugin for unchain SEH with restore original (system) handler exception and restore stack to original state (it can be changed by RTL start code)

Please Login or Register to see this Hidden Content

Plagin  for EOF (overlay) simulation for Сitadel і Zeus.

Please Login or Register to see this Hidden Content

Please Login or Register to see this Hidden Content

Attached Files


Edited by 0xDADA11C7, 28 December 2014 - 11:29 PM.

  • Pink, x58, Tigerass and 2 others like this

#2 Jochen

Jochen

    Intermediate Member

  • Notorious
  • 149 posts
Contributor

Posted 29 December 2014 - 06:42 AM

What's wrong with getting KernelBase like this , if you gonna use the PEB.

 

    proc GetKernel32
        MOV EAX, [FS:30h]
        MOV EAX, [EAX+0Ch]
        MOV EAX, [EAX+0Ch]
        MOV EAX, [EAX]
        MOV EAX, [EAX]
        MOV EAX, [EAX+18h]
        RET
        endp

 

 



#3 Tigerass

Tigerass

    Member

  • Loyalist
  • 709 posts
  • LocationNorthern Syria
Contributor

Posted 29 December 2014 - 10:46 AM

@Jochen because you are getting it "by luck". Most of the time it will go well, but the order of the loaded modules isnt fixed. So some av for eg. Could change it.
  • 0xDADA11C7 likes this



Also tagged with one or more of these keywords: source