Skip to content

Instantly share code, notes, and snippets.

#!/bin/bash
sudo iptables -t nat -a prerouting -p udp -d 8.8.8.8 --dport 53 -j redirect
sudo iptables -t nat -a prerouting -p tcp -d 8.8.8.8 --dport 53 -j redirect
u ntdll!ZwReadFile
ntdll!NtReadFile:
77f761e8 b8b7000000 mov eax,0xb7
77f761ed ba0003fe7f mov edx,0x7ffe0300
77f761f2 ffd2 call edx
77f761f4 c22400 ret 0x24
ln 0x7ffe0300
(7ffe0300) SharedUserData!SystemCallStub
Exact matches:
https://www.virustotal.com/gui/file/059d997835d4507156bc6ad26de10892dbe7b2353ed18f02ca27b1ec0b67f46f
https://www.virustotal.com/gui/file/688006b7100f49485de349daece4665de58a2ed1092a246f4157af481848d9bf
https://www.virustotal.com/gui/file/f0b2a1f0fccd298d048ef6c92168a8bbf18af019d74da7e3ba6c4e8a1c4949cc
https://www.virustotal.com/gui/file/91915970ec2b97673a351f52628d404b505ced5bab449c67d85c9745f5f04c7d