From a5cd3309b71e970f5f72b2e2a183ef7cef26b908 Mon Sep 17 00:00:00 2001 From: Dobin Rutishauser Date: Mon, 17 Jun 2024 09:27:02 +0200 Subject: [PATCH] tests: add dll_loader tests --- data/binary/shellcodes/createfile.dll | Bin 0 -> 11776 bytes data/binary/shellcodes/messagebox.dll | Bin 0 -> 10752 bytes tester.py | 30 ++++++++++++++++++++++++-- 3 files changed, 28 insertions(+), 2 deletions(-) create mode 100644 data/binary/shellcodes/createfile.dll create mode 100644 data/binary/shellcodes/messagebox.dll diff --git a/data/binary/shellcodes/createfile.dll b/data/binary/shellcodes/createfile.dll new file mode 100644 index 0000000000000000000000000000000000000000..fb045563daaf4027bd0488ec74f77cecd0d7e39e GIT binary patch literal 11776 zcmeHN4|G)3nZJ|dB_S|O&n0sCLBpTO3`y`(2OA*)DuKzr7npW3GduGJ z!KF2Hi0kk=XVKQxZvPyCJ+0QRi*8#3-EAj?HHkutxb1?%Htn9e4@2ANT18uZ`}^*D z6B4Yu=WMrU&u)Ei@Av0^-*>z~us@$Q-@nl2}MdXH$ua|qGT}qYRUgEY) z$NP`}#Z70waV}R@9$0#=8uYL4eEhr#A3MK9&`+GdMZmv3zXI^n2Obyvo6bIdZa(Pi zw;U4m^;^Di{$@e9oHOC0f?gNu+)jPuM%2{ESl7LUtmss!?|Qw7geii!%2-5Lil@yO`5D&Ezu zwllV2CRng3WM_-!iOPqrt4uL=9|Z^u1cR~bQ6@b;#-8^9&efZYHl#dTJxM>kFp0O`mz!=DiUXZZU=*@zXsgI*5KEwHm z`JyA9x@08h8_sngwNp@>14TW6-up=yefc&Ig8dOTO$6(mN(us+e$@YXcKFsd=+gNXt@pw`2ZZH~}}7+aIf9ELqA221>i%959Te zZIBO)lwPfcplUXHS4(n3s2J2&VdsoV`qcoA?_@E8iorD)FW?0S zI#}D6bv!sANZQvt-AePNx=VR_w_Emaz<^|~y%x}3^^WLI!N}gMWA88&^`#PH`_A0g z;P&~Rwx#Ok)PU*e`$yD6(lihhMSU-X_GZ-S6p^$aqB{&Q43<6K75kg?wgp#RGZ z#`?0!8}tRHxQzA^v;8+noO(anhoo;ISJ8I$RU7-B)9)<;w%16m)K37z%HgS6rnnWLnzM*9KR@&lUvUKsNm&l}Q@DseQCgJXH#EZ17ySdFT?mTSA+9I=r7 zTL+K8D${#W@27dCxQJ!z+xM0xJqZ22>^*i<*#{L*aL^b|OS{pa&&LQwWaLy`9yy)# z>RyaY|1suFf3lddRQW4NtPI2WK793__U-$jepbxT84*`)aO`WQ0|vPJ_n+X}ah~2J z2hu)Qx(Rc`i#Kc(ljB>XjcadXdiqW$9ZQ|RMUJ|s$eX?JbC}PpGE$dpclo#`y?!lX zgb+)aO|~&?r`@2nGZ>Vo?5si*7-+(d!qV9L`N>Tmo@h!Lw&YE) zR}D4qX;RBW8}EAqi%I|CyR=)RUb9biW=_U%N?`RFs+2PFlPe~Aym`WGUsf%L=IY7b zmgeLP=QAJ5c|BI>eTlr+25I(oVgh{rt--B>m)9>%mb^y0q`k1zZdSccOF9tKi$gx2248?eY{V^;LXKyj@Bt1K16_GY2%Hi zq!0LJu!f|?;83?i(v84q;SNblEUX{viSbWmX*X4p=1_r+dcMrp>lTW#sLCl4j1z>D1_I;o3#a9QLDh z_y!pNZuP;RRDO|$wR|wC@|04FUe=Zx&evdrYmL|ojpK&%A}B4(7Za|VcxJ83q(_Nv zbU|&L4~)v(3*6f{&bUc8(td)H|1Yb}ynWa<_9o>bvU`uITcjUEvKgDBZv&0g_lU_Z zsLqZR>0bnK*d{t89VGBdEFC292Tgl9TN>o{W|O3JmHru%DAJQa#x73M*E_+{x1zF` zxxC2JVLC5Vx69geZ&6ahzPq5GLHa_Pn4S8KEjdf%0j{0o+K}OV+ePDTc5l)G2(P&t z!`KkW!#=o-E%^iJim`rP7*R_R4sM~p;ccjcsQvu_FITvV9Hb>s@`r#RJxxAoEkR%-Eog3K>+J%CIFEHL0$v! zjPz6Nc$;uQ-aL2&#|G2iMkVGQN7_LD+B+HRUMk&>6_wn{JMG7T;K1BNAphAtOX*!C z8SI~qB+$Lo?@BfYZan6A`i?T5I_Bc}&pV#>7xK)E-aux?vpikqUbFmp)unxGMqv3s zyhK}7oIem)o{bknx?=1n-qRch3$2W@)ZK3OX~Igd4hsSE#Ike^nlajURv*Js^qxjs zrtf_zS;YU`Ig|1kWlBq?w=N$Xw(qQ3u=jLwhJF=Bhcj?GKyJXarZUnJhz+L7?IdmH z^cJ4^rrY-$3~|rJEabJbR<=Fu6jM>4J$LekBbZsHAIDCE-`MW{{!?&CPoN^waGr-S z*S?}djAtG^LwxNyWHiIMnOflbid-hkjEYtvbUB-0<7aegpnN7W3J{qNi-p2;->~S5 zmUOz0x*L%%TtK+t96%%GR-fT~0x0%@9lJ~|&hUJFK%Br|cAr9|_@3hwFyt)cS8<1tdFI*_ z9bB2Z-2h`(;dVr0FEpH8G>X(5BOB;V!cc<-Qp7_Z~dK%%TclfI7h?oSQd8q(62fsPe{_jw?Ajqq!)Hfm=Z zwdeh*cZ+r_{*1qfe1})sYj6nu!XdchIQp;C64PNM4@NdZ7Z?kAkS(oIUO2dH&>Yxb6x?17yy3bL`11}N ztR-ssNU~aVaBSJJL+YnRY3ap9Ftul-0@31cKF_bSe;b-SZGQp) z6S8AEPyO`!pucJw{FyURMh4N(=+%j7083J6ffKFnTDsz!M^Y(nm|O6=CKe^2H@j5Y z4LKaA6EAT_`2(|PE$$WdUy6EI)JH}AO;JB1>W4-Bl&DSl9l%eVIBXj<%GV1N*^r*g z?}Nsu$(dSDYA-(sMPCcfL78i>>|2ZA9+$UV*z`88x0Beiz8W05?8z9?M1v{(G>%o1 zhilj?T(fD|y2y8Ujh6!%`+ct(MnG$fX)UjUy=hv)wTQHYhIeF7E!IWW@r40x z0DLTw51v1Q2(&FX2N|*8XDm3o&g6S6*kHjn3x39e4_NSP7OcI+)LUr5Vhg@zwV$)# zF$?BdFc<2ltp5MXf&okav_b9QdE_&NIbh5LPGe;&UHbN1-%XYy0ema$f*GKKZvXU|sFZVA>$ zli@Czet++bEA6TxcZb4?T%p9{(YRdRbwi0Ix0=|dNSB;Qc6KU>M0YYA-en2+C1Z>s>Kkys(1kdg9 zO!#KX?G)cM==apB5Pg?$FCjgwMOI6C9#3cYHrN4OOmzJ^yaw0%NoLbj-krp2o5EWo zkP_@yL!TN6VDax%CE(!Q|2O;u^7&zhBueO zc%H{rU}FWVOij4YW;u(QQ=P_~T}8}UQ^=gvvql-#CWgT-&0=gD7BTG^dY%RTqe--| zS)JE3tE7OH)D*Llb%im~Er6`!YK#HpE0%5n@Kq?^vFO`?ZXo$>u0z4vfKpF*vHH$86JVY+47}iwjtBydaj} zhOtu&ssZf<%wAK%?CT1frcpc=!mwq(6Tig$0)@#YwB^}Y9u|bHteBN`p)?nfbkEwz zKAm@~q6XR%Y9rml82bXN4@VOUZ;y0^6?R+Wy4xEA-fFRMaMA>W^}$3;=?ry;I)mGV z40OuDPpDl%byrLYh9ce3U>D{(9^DlThiJ}kVLeJuLIJj+eqGD$&1=>+F0S#IHW_r= zJL76F6zvFhCnKF$vBFv?8tjbr^h6`U9o?~bD57@b#Dw*bsw(jwcJpOCsIZkRm{7I{ zaic_IkXE^iK|RtP+Lnwf!ALs>cUQ1IzHJA7y)ZRH?cvbf6HQ8FM<^bR^e7Q{Su;f< z8c}wJ)S%klfq<}uEU4^MI+LmroYF8G{gE7F?Xgg0Pona!P^1#$szhKy(aP}R%EguD zkgsURU!tg?9%Zt`uM5_x;rjNN3g7Fa_%REA5AhE10@3KFlCjl@k{XIe8Y60a7xJxy zmJOk}nrsiZM9?h`)R(1}h&er7jXOJ)7>Q%P5gf+;T3WBD@7r8W>!Cgwk0TOI@hDxs z*>R~EArD1xY0t6PqxowR77>lF#(f^XHpP_$1u#}{M^cIJYEt6e(RfdLq!XjSDABq1 zz1G)sv70Axo3~?ec7e%C^5Mz)T?tj`X-0tj30km(v3>b#unf!zTpz#^<4|Fbz@rAG zBe`vx63=vH<3{m>v`M(l@+}FDQuD>U@$fvvi$$TRv8@YE=I#=mlW8NqQBFNu$ z9*fows{fS;l;TcM_7qP?~`=+<9Cmt-zZABPiQR1~6;!3H}&&)G+vG05{>j zco;ZA`n$OTygU*72b3D%S-{s(HUTF%gcrC5;KP7RXXD)y_zFNBr49IuYZzOELOxUg zwp(}?;KLS9@NX>qFyI*rC-@5s9|vr5;k1QKg1snYli(LDoZt^E{1o8kIi{bjfUl#3 zYfb2yYw`*DExZ}<%k%KA0~vy6Q2K!r#P3G}cLDwk@5sl&Z^Qk!1LX|xUO>9@j{+x1 zclbx)8$r6i6Hbus;Di%oGXBmD@&sKdpCkN# ziA5`Kv6rl9Pb8F{j_@uS1|o^NMag(%S)y~h($k)(>Zrp`7Ozw?LeKcna#FY;IvC|&&Zzf#_Chj0p#Fc3|33f}7{6cu literal 0 HcmV?d00001 diff --git a/data/binary/shellcodes/messagebox.dll b/data/binary/shellcodes/messagebox.dll new file mode 100644 index 0000000000000000000000000000000000000000..c4517175432ebd1d7df7a0ce6bdb0fdba72ebdc9 GIT binary patch literal 10752 zcmeHN4RBOdmcE_jB_Yss&@>bA@1dPZP?BxZ5&1DgH%atG8;v1B1_GU?^8&4%?ym0F z5L~7V(?n?=?K0!I;^=JgGrOg`))emg6JqV!A&f}`b|5-4ATbD^kMiM2Xm!Nf#{0a%U`XOuiF_m$qTc|}WGn?~l zM$>klbQj0sB#@+7YUt= z?a?|U2C12`nSi?6nbsAFu9fm{L)EeMc%!{*DMMB!iR}_lu;4)^Q#Qr{N=rO?FN?Hz zB`?;C86pVSWaI+mG0BOp%XBrinH*zBhOZcG8k?LLZdq7Y)W!&brk7qMhBCy?vPd-I z1F!i6zR~o)Z73Mv)bzwa2#Vw*@|C6s-;PaA#ukp{zlpSKFTB9qN$!~`nDnIe6@X(v zP>Ysh;tw7?D8$c}#4nj*H;pLn(iPv*6jiGOdR?@@g!ulF-h+bN(~D{&$&nhz8uHdw z%dMLu+T&mM`@5HImKecVYfG-zcjls2WLhm@x# zfO{tkk8^mylV{MokTf3$C?8H@tTPpxq0G?Ld6akS<$p)zT`2G4wxUtm9?o)g%K_!- z98jCo*aGE!P=b6^h|gh?O_2MQXLp<8~Zn<~`G|18LvZrMB=jk(k#D)-m77_%~z z;YbN`lg%#3l5LJ4Z?FmQ1@BtfyBDo8Wiy`JFe{p09)UCL&MlwGoQV3JsVB^OWhbiG zJ-upwf^(xlDaHsj&+zfe4{nFiF^4iABU65bIaBuLG8Qk|2RXwq`e3VL(7ELo%1Ld8 zj%t3Ddx!o;Hz0=$*oJkpUq~$F-3e!5q7HK-qk)pV2ip@rQ<*4Quq-vjhuBt-kr&vtNFTMaNb9TK?X>wXewZ4vU z*r`ffT+NK#Gt%STBh7ZEq$1S(6lx>Z=BM>k>srWltB0~3$H{uRmu9aW6X0~M^sMY1 zUB5J0e64&@{y>n=(-!5F7qBGVa-aO3Knr4I(lOtj(=Whg%(HW`zTl5J22|^c=8D9C5gG4>(lW3*;}V`-EOMN7;p-GjxNp8azVac3qrRo*K$gegI~VN$Zg6 zAdr`0;UJJdtGAbKD-OL)sTftdPFbrnIZ7Ldp|fM^E6X8Kmf&Fsjk&`@4$!$F*$R!# z_ZbBz?7!2>Q3N-Hi>dL;rq~oM9tiRwLGDwnyKpejl36Od;bwhT2Cy*@kDV|XTk{>% z)yDda)`*l3XTOLzO9MLH1DW#1MOCHXrtH;J;aFpwuNwU6mox%rVvpPDkZ?kgzSsq^wPYu}MlEMu)R76ObM-t*In;1!}$VqTi6V9@`s*FP zAhM}eACAiB9T<4AF$H zuI<#T7WX?hlb!Fw+H?&ZyUl&owmK^=H^2r8@T&EnXrMe?%2WIRtDK{x(Dm~gs{G#nJ>1^Cj4nyohoXypCsF1w*0Xo2vmDPZu>u^h= zv1hB+N#urjZ>})^qsVD}SJGY_UspRHla+KXj;*V8c8$9Guz0C&Jw!Cp{Y8uQ`Hqxh zz_P1a?x~gsT^m2~2gO>~#^InO2CC%))$*`oK)cUccGXNgjA-xLc>X>y7)z}9L(Rk^ ziA5LX&k~KF$Ce9m^XquSQj3Ncs1~7*`w6{nbud<$$~G~nq_R0XgGtjX!vxc~J)eD! z%MriMChRrg7$rXomfbzkf@+ythcNGo_nWE{Tma-y4rD$MHI4z7e7;6LRwEyA#lOhe zAi9#S9I_o&$)CU=*b9STj-~rwCPXKqkqk6ajJmjpZMdNeF_R^QOElOIPzN=1^)4F< zs^<@HxL)_fdt(c66#g8q)o)=+FefLz=;OMIyen;&-AlIx-y=dVb3b6AufCMjlmfvcx~7w&WWAw%&QY7H#3mTm$O; z{fT&gZXf3YNqZ~7Edb^Ew1<~g#QXU^t^_O=7Ye=&YA>`7!|chRt8X8GJy&2LBX0gc ztX%70-@JXX>CicI9h_tSJ)TbJ9Z%eR5+t+-0Yf=Z7yx1EKJ~5WB*D@>T!^AKA#uUO z*GKOkY0Bx6-*w6Rgr3v+MJnFN<0o?x+}{?Wsf`0A@Ro4lh;Y04ds^G(wE#@W+KEE^ zzf(8F=s zs}?Q8bf`s5+HJ|qjdQRbQkEa}$UTr_Y5cED zO{KcoOJ?f0$-wOfzGmQ{fu{_-WZ+bz{#FCm8u+MDey_pX4NNR?YchZu}F+Yy{kojVW^$2Y4^5;10paSiqJkm>HrE&FKlH~QR(ds!V?0y}|81L0hU*z@i=T0B*hY`K6%bt-At|Dw-VTWN~ zzJY}X@&=X|NUf#6AtO++2ILkTel3X9l+tCBK-2k62V>V&WoF2iQg}q!!K=#f$>C3$ zsQJu}%#K3zRRP)!B-ukS?f~)$isPwc*`1~+}L?tqiD z@7T6BZM}EEj@c+r%WQW0h;6#8oiSejrd;Ny@6fippw6&1*&JY*-R^5$jnCKEA-Tj? z)#G)p$_0|m882H#GUqs1t)?f8muY%+<79Q3-qP_hO|N;JtU=SG-8yPZgQgdTjLzcp zw|R!SY=J#GZ(AD*NNvQ^dfY#vXM6nd$6Homc&wz@Xfq=DY_%?}ANx4jGOeFEV`UAx zo^zZ`*ApPyY(oF-`nUb`ZyRNz&eLxkb!4CJ^Ky_Z{|7 zX$*Q@nqKYqg$_XaH-`>8#)C^`*{W!iikXvMzrY*6HBjfx5Np3F*bs@4njzahD${Ht z`G1y7StgdXP`|ZKvF0+XG=W)La+tLun_0`JoUmgJ!dzB@&*sk|)83$T2{ebro90cp zy=Rwa)J@6DVtEz0EU!L0Om(xMy8wDCkq;SlD?mq(PZ|85gMM;MIq^@8DW5Pcn@y{* zuxXL0Ckn#XH&eTC2m43p{1|uFOW+AL8|pLaOqOhB!5AzUgQa|8*fhb!CagkvZWhap zWQ8-EGwg=Fc9S`anJe;`xjwsY0{P-LOo!3_3x$joA$HjDjfc>bVPYBZv#B7L6|^8X zG&k9 z!1^LNy;o4ah+w*VtHm9+!{ zY{3G1mBBlm57)R{&ZWyBtQaqJ)wq_}oi-a3fX=VfaMdg{%3FgYt$x=fP@AIyhu~ro z;v-qL1A8N#%CINed93j7)cFXK1$p13K)xJlsx z=3A|oAMQsxkI7HV&QvZL7(Ig1#5y*WIbXVhms}!h!pb%8iQyS zhtw&qF{rz=rKa5{hDrTiZSai!lv^xHUs+t9ai1tv#Uc@mv@R0z;R4O}a}98*Kj@Xj zw1~ZwSsOK&P~=|GOSaZU#3(r^ob_-_jI6H{BdwuGn>XmgC@@M)uj9+D*S4^`$4DF2 zL_}{3ge)%;mMmT$mBh9NILH;n07RnLmdsjAvpzwK-B=a^s<0ifs9IbVTfJJ0q%C=% zrvAYicY4j;Lu|sEBL|I_w^SRY9syXLUEVQJN-tX5gI!-PHWQt zfBcVnfXA8l5Hj7>I)HzLTnBmwaM+L&X5)^~KzBUgX5{U3w*%7uVa|dkJcoP}&e&m~ ztpH~!Xu=D~GeKVj`f+Km0384pPDQ_SOW=?=FIHW1SNjc7u;gAq+g_oV{p z6AH)@=&v`Kw0A$aqGNnNboYTB*O22!TPC24?#(|KUrFQcSVmfy0W;j;oj0Y#e7u4;pq+FxT!2&FGh+g1hE^JpL#tt^g3 zg7c!jHDa4LTH5CKMMBX~t5oU>waxQJ+sf9?D&`TW{jE4_myGR=n);I9uxP$G?-I>3$aA(QR_MII&*X-)pwRu