Giter VIP home page Giter VIP logo

x1ldr's Introduction

免责声明:本工具仅用于安全研究和教学目的,用户应自行承担因使用该工具而引起的一切法律和相关责任。作者不对任何法律责任承担责任。

更新日志

https://mp.weixin.qq.com/s/L3d7w-u__T1zeL5rze4M0A

经过删除 pdb 信息,加 icon 运行时库改为 /MT 后,可以某步全绿

读文件的方法改为 WINAPI

BypassAV-1

通过分离的方式规避杀软

读入 Msfvenom 或 Cobalt Strike 等 C2 的 Shellcode 方式分离免杀

或者配合 donut 可以将 exe、dll 转为 Shellcode 载入 MimiKatz 等工具

使用方法

使用 Visual Studio 2022 打开,然后选择 Release 编译

自定义一个 key,然后使用 xorencrypt.py 将 Shellcode 加密

> python .\xorencrypt.py .\calc.bin
> xor encrypted : .\calc_encrypted.bin

将加密后的文件名作为参数传递给 fopen

	//修改这里
	char key[] = "key";

	//修改这里
	fp = fopen("user.dat", "rb");

效果

img2

其他杀软请自测

demo

image-20231130151411386

更新记录

增加 xor 加密

x1ldr's People

Contributors

yutianqaq avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar

x1ldr's Issues

提示:未经处理的异常: 将一个无效参数传递给了将无效参数视为严重错

大佬,打扰一下。我是这样运行项目的。但是报错 希望大佬能帮助一下

第一:cs 生成一个Payload Generator————Raw 格式的payload.bin
第二:将payload.bin 复制到项目目录下,运行python3 xorencrypt.py payload.bin (xorencrypt.py中的key修改成为admin咯) 终端运行输出: xor encrypted : payload_encrypted.bin
第三:在Microsoft Visual Studio 中打开运行BypassAV-1.sln 然后选Release x64 本地 Windows 调试器运行发现报错

image image

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.