
Statically extracts and decrypts AES-CBC/XOR-obfuscated shellcode from laZzzy-wrapped PE binaries via signature matching and RIP-relative address resolution, without execution or emulation.
A static analysis tool for extracting encrypted shellcode from laZzzy-wrapped PE binaries without requiring dynamic execution, debugging, or emulation.
laZzzy Dump is a malware analysis tool which aids analysis through static extraction of shellcode from binaries compiled with laZzzy, an open-source shellcode loader that uses AES-CBC encryption combined with XOR obfuscation.
During incident response investigations involving multi-stage malware chains, manually decrypting laZzzy payloads is tedious and time-consuming. This tool automates the process by:
laZzzy produces a complete Windows PE executable that includes:
The AESDecrypt function compiled by laZzzy contains a recognizable instruction sequence:
The tool scans the binary for this pattern and locates the function without requiring a disassembler.
Once the function is found, the tool extracts operands from LEA and MOV instructions and resolves RIP-relative addresses to recover:
The extracted material is decrypted using:
The result is the raw shellcode ready for further analysis.
pip install pefile pycryptodome
./laZzzy_dump.py -n <path_to_lazzy_binary>
./laZzzy_dump.py -n malware.exe
The tool prints:
<binary_path>_dumped[+] Processing malware.exe
[+] Found AESDecrypt function: Virtual Address:0x140026db0 File Offset:0x2db0
[+] Key:
[+] 0002f010 48 c2 f4 a1 12 34 56 78 9a bc de f0 11 22 33 44 |H..q...x......"3D|
[+] IV:
[+] 0002f020 55 66 77 88 99 aa bb cc dd ee ff 00 11 22 33 44 |Ufgw............"3D|
[+] XOR Key:
[+] 0002f030 aa bb cc dd ee ff 00 11 22 33 44 55 66 77 88 99 |......"3DUfw....|
[+] Writing shellcode to malware.exe_dumped
The tool has been validated against multiple independently generated laZzzy samples with varying build configurations and payload types. The signature pattern successfully locates the AESDecrypt function across these samples without false positives.
This tool is provided for educational and authorized security research purposes only. Unauthorized access to computer systems is illegal. Use only on systems you own or have explicit permission to test.