Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| en:it-security:blog:obfuscation_polymorphic_in_memory_decoder [2024/09/23 09:03] – psycore | en:it-security:blog:obfuscation_polymorphic_in_memory_decoder [2024/10/15 19:30] (current) – psycore | ||
|---|---|---|---|
| Line 143: | Line 143: | ||
| <code python> | <code python> | ||
| - | python shencode.py extract -f calc.o -o calc.raw -fb 60 -lb 311 | + | python shencode.py extract -i calc.o -o calc.raw -fb 60 -lb 311 | 
| ... | ... | ||
| - | python shencode.py  | + | python shencode.py  | 
| ... | ... | ||
| - | python shencode.py  | + | python shencode.py  | 
| [*] processing shellcode format... | [*] processing shellcode format... | ||
| 0x6a, | 0x6a, | ||
| Line 188: | Line 188: | ||
| <code python> | <code python> | ||
| - | python shencode.py  | + | python shencode.py  | 
| 0x00000048: 00 00 00 00 00 00 00 00 | 0x00000048: 00 00 00 00 00 00 00 00 | ||
| Line 198: | Line 198: | ||
| 0x00000336: 00 00 00 00 00 fe ff 00 | 0x00000336: 00 00 00 00 00 fe ff 00 | ||
| - | python shencode.py extract -f xor-decoder.o -o xor-decoder.stub -fb 60 -lb 329 | + | python shencode.py extract -i xor-decoder.o -o xor-decoder.stub -fb 60 -lb 329 | 
| [*] try to open file | [*] try to open file | ||
| Line 206: | Line 206: | ||
| [+] DONE! | [+] DONE! | ||
| - | python shencode.py  | + | python shencode.py  | 
| [*] processing shellcode format... | [*] processing shellcode format... | ||
| Line 263: | Line 263: | ||
| <code python> | <code python> | ||
| - | python shencode.py  | + | python shencode.py  | 
| - | python shencode.py  | + | python shencode.py  | 
| </ | </ | ||