从加密的zip中执行位置无关的shellcode 通过donut、metasploit或cobaltstrike的RAW格式获取你的汇编PIC代码。
将.bin文件压缩并加密,该程序集在内存中解密zip条目并使用D/Invokes注入API执行。
能够注入到正在运行的进程中,或先创建一个新进程再注入到新创建的进程中。 理论上自我注入可行,但会导致崩溃。因为自我注入并非我的主要目标,所以没有真正尝试修复该问题。
通过将加密的zip放在磁盘上进行测试,但可能经过一些修改后也能完全在内存中工作。 仅支持PIC载荷,曾尝试创建runPE变体但失败得很惨 :)
___ _ ____ _ ___
/ __>| |_ ___ _ _ ___ |_ /<_> ___ | . \ _ _ ._ _ ._ _ ___ _ _
\__ \| . |<_> || '_>| . \ / / | || . \| /| | || ' || ' |/ ._>| '_>
<___/|_|_|<___||_| | _//___||_|| _/|_\_\`___||_|_||_|_|\___.|_|
|_| |_|
An Encrypted zip on your computer? what could possibly go wrong?
Usage:
-z, --zip-file=VALUE The path on disk to the encrypted zip
-e, --entry=VALUE The specific zip entry to put in mem (optional),
if not provided assumes only one zip entry is
present
-p, --password=VALUE The password of the encrypted zip
-i, --process=VALUE The process to inject into (if not used will
inject into self (not recommended)
-c, --create Create a new process, and injects into that
process (requires the process argument)
-h, --help shows this menu