├── _config.yml
├── .gitattributes
├── ShellcodeLoader
├── stdafx.h
├── stdafx.cpp
├── targetver.h
├── shellcode64.bin
├── shellcodex86.bin
├── ShellcodeLoader.cpp
├── ShellcodeLoader.vcxproj.filters
├── ShellcodeLoader.vcxproj
└── argparse.hpp
├── ShellcodeLoader.sln
├── README.md
└── .gitignore
/_config.yml:
--------------------------------------------------------------------------------
1 | theme: jekyll-theme-slate
--------------------------------------------------------------------------------
/.gitattributes:
--------------------------------------------------------------------------------
1 | # Auto detect text files and perform LF normalization
2 | * text=auto
3 |
--------------------------------------------------------------------------------
/ShellcodeLoader/stdafx.h:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/sisoma2/ShellcodeLoader/HEAD/ShellcodeLoader/stdafx.h
--------------------------------------------------------------------------------
/ShellcodeLoader/stdafx.cpp:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/sisoma2/ShellcodeLoader/HEAD/ShellcodeLoader/stdafx.cpp
--------------------------------------------------------------------------------
/ShellcodeLoader/targetver.h:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/sisoma2/ShellcodeLoader/HEAD/ShellcodeLoader/targetver.h
--------------------------------------------------------------------------------
/ShellcodeLoader/shellcode64.bin:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/sisoma2/ShellcodeLoader/HEAD/ShellcodeLoader/shellcode64.bin
--------------------------------------------------------------------------------
/ShellcodeLoader/shellcodex86.bin:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/sisoma2/ShellcodeLoader/HEAD/ShellcodeLoader/shellcodex86.bin
--------------------------------------------------------------------------------
/ShellcodeLoader/ShellcodeLoader.cpp:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/sisoma2/ShellcodeLoader/HEAD/ShellcodeLoader/ShellcodeLoader.cpp
--------------------------------------------------------------------------------
/ShellcodeLoader/ShellcodeLoader.vcxproj.filters:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 | {4FC737F1-C7A5-4376-A066-2A32D752A2FF}
6 | cpp;c;cc;cxx;def;odl;idl;hpj;bat;asm;asmx
7 |
8 |
9 | {93995380-89BD-4b04-88EB-625FBE52EBFB}
10 | h;hh;hpp;hxx;hm;inl;inc;xsd
11 |
12 |
13 | {67DA6AB6-F800-4c08-8B7A-83BB121AAD01}
14 | rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms
15 |
16 |
17 |
18 |
19 | Archivos de encabezado
20 |
21 |
22 | Archivos de encabezado
23 |
24 |
25 |
26 |
27 | Archivos de origen
28 |
29 |
30 | Archivos de origen
31 |
32 |
33 |
--------------------------------------------------------------------------------
/ShellcodeLoader.sln:
--------------------------------------------------------------------------------
1 |
2 | Microsoft Visual Studio Solution File, Format Version 12.00
3 | # Visual Studio 15
4 | VisualStudioVersion = 15.0.27130.2020
5 | MinimumVisualStudioVersion = 10.0.40219.1
6 | Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "ShellcodeLoader", "ShellcodeLoader\ShellcodeLoader.vcxproj", "{8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}"
7 | EndProject
8 | Global
9 | GlobalSection(SolutionConfigurationPlatforms) = preSolution
10 | Debug|x64 = Debug|x64
11 | Debug|x86 = Debug|x86
12 | Release|x64 = Release|x64
13 | Release|x86 = Release|x86
14 | EndGlobalSection
15 | GlobalSection(ProjectConfigurationPlatforms) = postSolution
16 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Debug|x64.ActiveCfg = Debug|x64
17 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Debug|x64.Build.0 = Debug|x64
18 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Debug|x86.ActiveCfg = Debug|Win32
19 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Debug|x86.Build.0 = Debug|Win32
20 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Release|x64.ActiveCfg = Release|x64
21 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Release|x64.Build.0 = Release|x64
22 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Release|x86.ActiveCfg = Release|Win32
23 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}.Release|x86.Build.0 = Release|Win32
24 | EndGlobalSection
25 | GlobalSection(SolutionProperties) = preSolution
26 | HideSolutionNode = FALSE
27 | EndGlobalSection
28 | GlobalSection(ExtensibilityGlobals) = postSolution
29 | SolutionGuid = {C4EC72CB-B9DF-4303-BCAE-16246B980B33}
30 | EndGlobalSection
31 | EndGlobal
32 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # ShellcodeLoader
2 |
3 | ShellcodeLoader has been built with the purpose to quickly debug a shellcode extracted in malware analysis in a context of an executable.
4 | What ShelcodeLoader does is read a bynary file from disk to memory and jump to the base or an especified entry point to execute the file.
5 | It autodetects if it's being debugged and asks the user if he/she wants to set a breakpoint before the execution of the shellcode.
6 | Works in x86 and x64 systems.
7 |
8 | ## Releases
9 |
10 | Go to the Releases tab and download the compiled executables.
11 |
12 | ## Usage
13 |
14 | The file is required. The other arguments are optional.
15 | ```
16 | ShellcodeLoader.exe [-e --entrypoint ENTRYPOINT] [-a --address ADDRESS] [-r --run] [-b --break] FILE
17 | ```
18 |
19 | Loads the file and executes the code at a specified offset
20 | ```
21 | ShellcodeLoader.exe -e 1000 shellcodex86.bin
22 | ```
23 |
24 | Reads the file and tries to allocate memory at the specified address and copy the shellcode to this region and execute it
25 | ```
26 | ShellcodeLoader.exe -a 30000 shellcodex86.bin
27 | ```
28 |
29 | Runs the shellcode without stopping or breaking. __Warning:__ The shellcode will be executed in your machine.
30 | ```
31 | ShellcodeLoader.exe -r shellcodex86.bin
32 | ```
33 |
34 | Tries to copy the shellcode at the specified region and sets a breakpoint before jumping to the specified entrypoint
35 | ```
36 | ShellcodeLoader.exe -a 30000 -e 1000 -b shellcodex86.bin
37 | ```
38 |
39 | ## Building
40 | __Requirements__
41 | - Download and install Microsoft Visual C++ Build Tools or Visual Studio
42 |
43 | __Build Steps__
44 | - Clone the repo and navigate to the directory
45 | - Open the SLN file to open the project to Visual Studio
46 | - Select the platform in which you will be compiling the binary (x32 or x64)
47 | - Go to Compile->Compile Solution to generate the EXE file
48 |
49 | ## Shellcode Samples
50 |
51 | The files shellcodex86.bin and shellcodex64.bin are shellcodes compiled with NASM that execute a calc.exe via WinExec Windows API for the purpose to test the software.
52 |
53 | ## Feedback
54 |
55 | Any questions, comments or requests you can find me on twitter: [@sisoma2](https://twitter.com/sisoma2)
56 | Pull requests welcome!
57 |
--------------------------------------------------------------------------------
/.gitignore:
--------------------------------------------------------------------------------
1 | ## Ignore Visual Studio temporary files, build results, and
2 | ## files generated by popular Visual Studio add-ons.
3 |
4 | # User-specific files
5 | *.suo
6 | *.user
7 | *.userosscache
8 | *.sln.docstates
9 |
10 | # User-specific files (MonoDevelop/Xamarin Studio)
11 | *.userprefs
12 |
13 | # Build results
14 | [Dd]ebug/
15 | [Dd]ebugPublic/
16 | [Rr]elease/
17 | [Rr]eleases/
18 | x64/
19 | x86/
20 | bld/
21 | [Bb]in/
22 | [Oo]bj/
23 | [Ll]og/
24 |
25 | # Visual Studio 2015 cache/options directory
26 | .vs/
27 | # Uncomment if you have tasks that create the project's static files in wwwroot
28 | #wwwroot/
29 |
30 | # MSTest test Results
31 | [Tt]est[Rr]esult*/
32 | [Bb]uild[Ll]og.*
33 |
34 | # NUNIT
35 | *.VisualState.xml
36 | TestResult.xml
37 |
38 | # Build Results of an ATL Project
39 | [Dd]ebugPS/
40 | [Rr]eleasePS/
41 | dlldata.c
42 |
43 | # DNX
44 | project.lock.json
45 | project.fragment.lock.json
46 | artifacts/
47 |
48 | *_i.c
49 | *_p.c
50 | *_i.h
51 | *.ilk
52 | *.meta
53 | *.obj
54 | *.pch
55 | *.pdb
56 | *.pgc
57 | *.pgd
58 | *.rsp
59 | *.sbr
60 | *.tlb
61 | *.tli
62 | *.tlh
63 | *.tmp
64 | *.tmp_proj
65 | *.log
66 | *.vspscc
67 | *.vssscc
68 | .builds
69 | *.pidb
70 | *.svclog
71 | *.scc
72 |
73 | # Chutzpah Test files
74 | _Chutzpah*
75 |
76 | # Visual C++ cache files
77 | ipch/
78 | *.aps
79 | *.ncb
80 | *.opendb
81 | *.opensdf
82 | *.sdf
83 | *.cachefile
84 | *.VC.db
85 | *.VC.VC.opendb
86 |
87 | # Visual Studio profiler
88 | *.psess
89 | *.vsp
90 | *.vspx
91 | *.sap
92 |
93 | # TFS 2012 Local Workspace
94 | $tf/
95 |
96 | # Guidance Automation Toolkit
97 | *.gpState
98 |
99 | # ReSharper is a .NET coding add-in
100 | _ReSharper*/
101 | *.[Rr]e[Ss]harper
102 | *.DotSettings.user
103 |
104 | # JustCode is a .NET coding add-in
105 | .JustCode
106 |
107 | # TeamCity is a build add-in
108 | _TeamCity*
109 |
110 | # DotCover is a Code Coverage Tool
111 | *.dotCover
112 |
113 | # NCrunch
114 | _NCrunch_*
115 | .*crunch*.local.xml
116 | nCrunchTemp_*
117 |
118 | # MightyMoose
119 | *.mm.*
120 | AutoTest.Net/
121 |
122 | # Web workbench (sass)
123 | .sass-cache/
124 |
125 | # Installshield output folder
126 | [Ee]xpress/
127 |
128 | # DocProject is a documentation generator add-in
129 | DocProject/buildhelp/
130 | DocProject/Help/*.HxT
131 | DocProject/Help/*.HxC
132 | DocProject/Help/*.hhc
133 | DocProject/Help/*.hhk
134 | DocProject/Help/*.hhp
135 | DocProject/Help/Html2
136 | DocProject/Help/html
137 |
138 | # Click-Once directory
139 | publish/
140 |
141 | # Publish Web Output
142 | *.[Pp]ublish.xml
143 | *.azurePubxml
144 | # TODO: Comment the next line if you want to checkin your web deploy settings
145 | # but database connection strings (with potential passwords) will be unencrypted
146 | #*.pubxml
147 | *.publishproj
148 |
149 | # Microsoft Azure Web App publish settings. Comment the next line if you want to
150 | # checkin your Azure Web App publish settings, but sensitive information contained
151 | # in these scripts will be unencrypted
152 | PublishScripts/
153 |
154 | # NuGet Packages
155 | *.nupkg
156 | # The packages folder can be ignored because of Package Restore
157 | **/packages/*
158 | # except build/, which is used as an MSBuild target.
159 | !**/packages/build/
160 | # Uncomment if necessary however generally it will be regenerated when needed
161 | #!**/packages/repositories.config
162 | # NuGet v3's project.json files produces more ignoreable files
163 | *.nuget.props
164 | *.nuget.targets
165 |
166 | # Microsoft Azure Build Output
167 | csx/
168 | *.build.csdef
169 |
170 | # Microsoft Azure Emulator
171 | ecf/
172 | rcf/
173 |
174 | # Windows Store app package directories and files
175 | AppPackages/
176 | BundleArtifacts/
177 | Package.StoreAssociation.xml
178 | _pkginfo.txt
179 |
180 | # Visual Studio cache files
181 | # files ending in .cache can be ignored
182 | *.[Cc]ache
183 | # but keep track of directories ending in .cache
184 | !*.[Cc]ache/
185 |
186 | # Others
187 | ClientBin/
188 | ~$*
189 | *~
190 | *.dbmdl
191 | *.dbproj.schemaview
192 | *.jfm
193 | *.pfx
194 | *.publishsettings
195 | node_modules/
196 | orleans.codegen.cs
197 |
198 | # Since there are multiple workflows, uncomment next line to ignore bower_components
199 | # (https://github.com/github/gitignore/pull/1529#issuecomment-104372622)
200 | #bower_components/
201 |
202 | # RIA/Silverlight projects
203 | Generated_Code/
204 |
205 | # Backup & report files from converting an old project file
206 | # to a newer Visual Studio version. Backup files are not needed,
207 | # because we have git ;-)
208 | _UpgradeReport_Files/
209 | Backup*/
210 | UpgradeLog*.XML
211 | UpgradeLog*.htm
212 |
213 | # SQL Server files
214 | *.mdf
215 | *.ldf
216 |
217 | # Business Intelligence projects
218 | *.rdl.data
219 | *.bim.layout
220 | *.bim_*.settings
221 |
222 | # Microsoft Fakes
223 | FakesAssemblies/
224 |
225 | # GhostDoc plugin setting file
226 | *.GhostDoc.xml
227 |
228 | # Node.js Tools for Visual Studio
229 | .ntvs_analysis.dat
230 |
231 | # Visual Studio 6 build log
232 | *.plg
233 |
234 | # Visual Studio 6 workspace options file
235 | *.opt
236 |
237 | # Visual Studio LightSwitch build output
238 | **/*.HTMLClient/GeneratedArtifacts
239 | **/*.DesktopClient/GeneratedArtifacts
240 | **/*.DesktopClient/ModelManifest.xml
241 | **/*.Server/GeneratedArtifacts
242 | **/*.Server/ModelManifest.xml
243 | _Pvt_Extensions
244 |
245 | # Paket dependency manager
246 | .paket/paket.exe
247 | paket-files/
248 |
249 | # FAKE - F# Make
250 | .fake/
251 |
252 | # JetBrains Rider
253 | .idea/
254 | *.sln.iml
255 |
256 | # CodeRush
257 | .cr/
258 |
259 | # Python Tools for Visual Studio (PTVS)
260 | __pycache__/
261 | *.pyc
--------------------------------------------------------------------------------
/ShellcodeLoader/ShellcodeLoader.vcxproj:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 | Debug
6 | Win32
7 |
8 |
9 | Release
10 | Win32
11 |
12 |
13 | Debug
14 | x64
15 |
16 |
17 | Release
18 | x64
19 |
20 |
21 |
22 | 15.0
23 | {8FBFBBE9-601F-46D7-A045-7FD6E7E502C1}
24 | Win32Proj
25 | ShellcodeLoader
26 | 10.0.16299.0
27 |
28 |
29 |
30 | Application
31 | true
32 | v141
33 | Unicode
34 |
35 |
36 | Application
37 | false
38 | v141
39 | true
40 | Unicode
41 |
42 |
43 | Application
44 | true
45 | v141
46 | Unicode
47 |
48 |
49 | Application
50 | false
51 | v141
52 | true
53 | Unicode
54 |
55 |
56 |
57 |
58 |
59 |
60 |
61 |
62 |
63 |
64 |
65 |
66 |
67 |
68 |
69 |
70 |
71 |
72 |
73 |
74 | true
75 |
76 |
77 | true
78 |
79 |
80 | false
81 |
82 |
83 | false
84 |
85 |
86 |
87 | Use
88 | Level3
89 | Disabled
90 | true
91 | WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)
92 | true
93 | MultiThreadedDebug
94 |
95 |
96 | Console
97 | true
98 | false
99 |
100 |
101 |
102 |
103 | Use
104 | Level3
105 | Disabled
106 | true
107 | _DEBUG;_CONSOLE;%(PreprocessorDefinitions)
108 | true
109 |
110 |
111 | Console
112 | true
113 |
114 |
115 |
116 |
117 | Use
118 | Level3
119 | MaxSpeed
120 | true
121 | true
122 | true
123 | WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)
124 | true
125 | MultiThreaded
126 |
127 |
128 | Console
129 | true
130 | true
131 | true
132 |
133 |
134 |
135 |
136 | Use
137 | Level3
138 | MaxSpeed
139 | true
140 | true
141 | true
142 | NDEBUG;_CONSOLE;%(PreprocessorDefinitions)
143 | true
144 |
145 |
146 | Console
147 | true
148 | true
149 | true
150 |
151 |
152 |
153 |
154 |
155 |
156 |
157 |
158 |
159 | Create
160 | Create
161 | Create
162 | Create
163 |
164 |
165 |
166 |
167 |
168 |
--------------------------------------------------------------------------------
/ShellcodeLoader/argparse.hpp:
--------------------------------------------------------------------------------
1 | #ifndef ARGPARSE_HPP_
2 | #define ARGPARSE_HPP_
3 |
4 | #if __cplusplus >= 201103L
5 | #include
6 | typedef std::unordered_map IndexMap;
7 | #else
8 | #include