用于 donut 二进制混淆器 的配置和模块提取器
donut-decryptor 会检查文件是否包含 donut 混淆器加载器 shellcode 的已知特征。如果找到,它会解析 shellcode 以定位、解密并提取嵌入在二进制文件中的 DONUT_INSTANCE 结构,并报告相关的配置数据。如果二进制文件中存在 DONUT_MODULE,则会对其进行解密并转储到磁盘。
你可以通过导航到项目的根目录并使用 pip 来安装 donut-decryptor:
cd /path/to/donut-decryptor
python -m pip install .
安装完成后,会提供一个命令行脚本。使用说明请运行:
donut-decryptor --help
本项目使用 Hatch 进行项目管理,使用 Ruff 进行代码检查与格式化,并使用 mypy 进行类型检查。
安装 Hatch:
pip install hatch
hatch run test
hatch run test-cov # 带覆盖率
hatch run lint:style # 检查代码风格
hatch run lint:fmt # 格式化代码并修复问题
hatch run lint:typing # 运行 mypy 类型检查
hatch run lint:all # 运行所有检查
samples 目录中的文件是使用密码 infected 保护的 7z 文件,其中都包含可使用此脚本解码的 donut。