ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

Binder (2 exes in one)


  • Please log in to reply
Binder (2 exes in one)

#1

TheLord
TheLord
    Offline
    13
    Rep
    96
    Likes

    SYSENTER

Posts: 164
Threads: 24
Joined: Jan 15, 2015
Credits: 0
Eight years registered
#1
This source of simple binder.
It seek "---HACKERS_CUT_HERE---" and load all bytes past this text. Then xoring it with 0xFF + pos key. When deciphering is done, starts new process, system32/lsass.exe, frozing it, load EP from EAX and clear all process memory. After this, writing deciphered bytes to lsass process and replacing EAX with his own entrypoint address. Dont work when binded exe is non-ASLR on ASLR systems.

This method is called thread inject or something similiar.

 
Hidden Content
You'll be able to see the hidden content once you reply to this topic or

Please Login or Register to see this Hidden Content

.

  • 2

#2

rambo 5
rambo 5
    Offline
    2
    Rep
    7
    Likes

    Member

  • PipPipPip
Posts: 28
Threads: 0
Joined: Jan 21, 2015
Credits: 0
Eight years registered
#2

wow nice thanks :)


  • 1

#3

pruned_14736011
pruned_14736011
    Offline
    2
    Rep
    0
    Likes

    Member

  • PipPipPip
Posts: 54
Threads: 0
Joined: Jan 31, 2015
Credits: 0
Eight years registered
#3

thanks a lot


  • 0

#4

m.willys
m.willys
    Offline
    2
    Rep
    0
    Likes

    Lurker

Posts: 2
Threads: 0
Joined: Feb 04, 2015
Credits: 0
Eight years registered
#4

thanks a lot :)


  • 0

#5

pruned_1821534
pruned_1821534
    Offline
    2
    Rep
    0
    Likes

    Addicted

  • PipPipPipPipPip
Posts: 200
Threads: 2
Joined: Feb 16, 2015
Credits: 0
Eight years registered
#5

THANKS


  • 0

#6

rer1001
rer1001
    Offline
    2
    Rep
    0
    Likes

    New Member

Posts: 18
Threads: 0
Joined: Feb 24, 2015
Credits: 0
Eight years registered
#6

THANK YOU VERY GOOD


  • 0

#7

ggnoobs
ggnoobs
    Offline
    2
    Rep
    4
    Likes

    Junkie

Posts: 349
Threads: 3
Joined: Jan 30, 2015
Credits: 0
Eight years registered
#7

This source of simple binder.
It seek "---HACKERS_CUT_HERE---" and load all bytes past this text. Then xoring it with 0xFF + pos key. When deciphering is done, starts new process, system32/lsass.exe, frozing it, load EP from EAX and clear all process memory. After this, writing deciphered bytes to lsass process and replacing EAX with his own entrypoint address. Dont work when binded exe is non-ASLR on ASLR systems.

This method is called thread inject or something similiar.

 

nice photo


  • 0

#8

notcomments
notcomments
    Offline
    2
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: Feb 26, 2015
Credits: 0
Eight years registered
#8

TNAKS!


  • 0

#9

marijuana
marijuana
    Offline
    2
    Rep
    0
    Likes

    Lurker

Posts: 5
Threads: 0
Joined: Mar 05, 2015
Credits: 0
Eight years registered
#9

thx


  • 0

#10

yoshino
yoshino
    Offline
    2
    Rep
    0
    Likes

    Advanced Member

Posts: 105
Threads: 0
Joined: Mar 17, 2015
Credits: 0
Eight years registered
#10

thanks


  • 0


 Users browsing this thread: