PhieuLang

ShellCode

Mar 23rd, 2015
304
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.46 KB | None | 0 0
  1. 00000000 EB4D jmp short 0x4f
  2. 00000002 5E pop si
  3. 00000003 6683EC0C sub esp,byte +0xc
  4. 00000007 48 dec ax
  5. 00000008 89E0 mov ax,sp
  6. 0000000A 48 dec ax
  7. 0000000B 31C9 xor cx,cx
  8. 0000000D 683E60 push word 0x603e
  9. 00000010 E7F7 out 0xf7,ax
  10. 00000012 48 dec ax
  11. 00000013 89CF mov di,cx
  12. 00000015 80C10C add cl,0xc
  13. 00000018 40 inc ax
  14. 00000019 8A3E40F6 mov bh,[0xf640]
  15. 0000001D D7 xlatb
  16. 0000001E 40 inc ax
  17. 0000001F 8838 mov [bx+si],bh
  18. 00000021 48 dec ax
  19. 00000022 FFC6 inc si
  20. 00000024 68BEFA push word 0xfabe
  21. 00000027 3911 cmp [bx+di],dx
  22. 00000029 48 dec ax
  23. 0000002A FFC0 inc ax
  24. 0000002C E2EA loop 0x18
  25. 0000002E 2C0C sub al,0xc
  26. 00000030 48 dec ax
  27. 00000031 89C6 mov si,ax
  28. 00000033 682977 push word 0x7729
  29. 00000036 1C9E sbb al,0x9e
  30. 00000038 48 dec ax
  31. 00000039 31C0 xor ax,ax
  32. 0000003B 48 dec ax
  33. 0000003C 89C7 mov di,ax
  34. 0000003E 0401 add al,0x1
  35. 00000040 48 dec ax
  36. 00000041 89C2 mov dx,ax
  37. 00000043 80C20B add dl,0xb
  38. 00000046 0F05 loadall286
  39. 00000048 48 dec ax
  40. 00000049 31C0 xor ax,ax
  41. 0000004B 043C add al,0x3c
  42. 0000004D 0F05 loadall286
  43. 0000004F E8AEFF call word 0x0
  44. 00000052 FF db 0xff
  45. 00000053 FFAE88CF jmp word far [bp-0x3078]
  46. 00000057 A8CD test al,0xcd
  47. 00000059 8B87A888 mov ax,[bx-0x7758]
  48. 0000005D AE scasb
  49. 0000005E AA stosb
  50. 0000005F B296 mov dl,0x96
  51. 00000061 75D6 jnz 0x39
  52. 00000063 04C0 add al,0xc0
  53. 00000065 F9 stc
  54. 00000066 6856DB push word 0xdb56
  55. 00000069 E84F5B call word 0x5bbb
  56. 0000006C 52 push dx
  57. 0000006D 41 inc cx
  58. 0000006E 4E dec si
  59. 0000006F 44 inc sp
  60. 00000070 53 push bx
  61. 00000071 54 push sp
  62. 00000072 52 push dx
  63. 00000073 32 db 0x32
  64. 00000074 5D pop bp
Advertisement
Add Comment
Please, Sign In to add comment