I have developed a fast emulator for modern shellcodes, that perform huge loops of millions of instructions emulated for resolving API or for other stuff.
The emulator is in Rust and all the few dependencies as well, so the rust safety is good for emulating malware.
There are shellcodes that can be emulated from the beginning to the end, but when this is not possible the tool has many features that can be used like a console, a memory tracing, register tracing, and so on.
https://github.com/sha0coder/scemu
In less than two seconds we have emulated 7 millions of instructions arriving to the recv.
At this point we have some IOC like the ip:port where it's connecting and other details.
Lets see what happens after the recv() spawning a console at position: 7,012,204
target/release/scemu -f shellcodes/shikata.bin -vv -c 7012204
The "ret" instruction is going to jump to the buffer read with recv() so is a kind of stager.
The option "-e" or "--endpoint" is not ready for now, but it will allow to proxy the calls to get the next stage automatically, but for now we have the details to get the stage.
SCEMU also identify all the Linux syscalls for 32bits shellcodes:
The encoder used in shellgen is also supported https://github.com/MarioVilas/shellgen
Let's check with cobalt-strike:
In verbose mode we could do several greps to see the calls and correlate with ghidra/ida/radare or for example grep the branches to study the emulation flow.
target/release/scemu -f shellcodes/rshell_sgn.bin -vv | grep j
target/release/scemu -f shellcodes/rshell_sgn.bin -vv -c 44000 -l
More info
- Hack Tools For Windows
- Hacking Tools Hardware
- Pentest Tools Alternative
- How To Hack
- Hacking Tools
- Pentest Tools Github
- Hacker Tools 2019
- How To Install Pentest Tools In Ubuntu
- Pentest Tools For Windows
- Hacker Tools Mac
- Pentest Tools Apk
- Hacking Tools Online
- Pentest Tools Github
- Hack Tool Apk
- Hack Tools Pc
- Hacking Tools For Windows 7
- Hacking Tools Download
- Pentest Reporting Tools
- Pentest Tools Bluekeep
- How To Hack
- Hacker Tools Online
- Hack Tools Pc
- Hack Tools For Pc
- Hack Tools Mac
- Hacker Tools Apk Download
- World No 1 Hacker Software
- How To Install Pentest Tools In Ubuntu
- Hack Tools For Games
- Termux Hacking Tools 2019
- How To Hack
- Pentest Tools For Android
- Pentest Tools Download
- Hack Tools For Pc
- Pentest Tools Download
- Hack Tools Online
- Physical Pentest Tools
- Hack Rom Tools
- Hack Tool Apk
- Hacking Tools 2020
- Hacker Tool Kit
- Hacker Tools For Mac
- Hack Tools Github
- Best Hacking Tools 2020
- Hacker Security Tools
- Hacker Tools For Mac
- Hackrf Tools
- Hack App
- Hacker Tools Mac
- Hack Tools Download
- Hacking Tools For Games
- New Hack Tools
- Blackhat Hacker Tools
- Tools Used For Hacking
- Hacking Tools Online
- Hacking Tools Mac
- Pentest Tools Windows
- Hacker Tools For Pc
- Hacker Tools Mac
- Hacking Tools 2019
- Hacking Tools Mac
- Pentest Tools For Android
- Hacking App
- Game Hacking
- Termux Hacking Tools 2019
- Blackhat Hacker Tools
- Pentest Tools For Android
- Hacker Tools For Windows
- Easy Hack Tools
- Growth Hacker Tools
- Pentest Box Tools Download
- Hacking Tools For Beginners
- Hacker Tools Apk Download
- Blackhat Hacker Tools
- Pentest Tools Kali Linux
- Android Hack Tools Github
- Pentest Tools
- Hackrf Tools
- Hacker Tools Apk Download
- Hacking Tools For Games
- Hacks And Tools
- Pentest Tools
- Hack And Tools
- Hacker Tools Apk
- Github Hacking Tools
- New Hacker Tools
- Usb Pentest Tools
- Hacking Tools For Pc
- Hack Apps
- How To Install Pentest Tools In Ubuntu
- Hacking Tools For Windows
- What Are Hacking Tools
- Pentest Tools For Android
- Hack Tools
- Hack Tool Apk
- Hacking Tools Usb
- Hack Tools For Mac
- Hack Tools For Windows
- Pentest Tools Open Source
- Hacking Tools Software
- Game Hacking
- Computer Hacker
- Hacking Tools For Windows 7
- Nsa Hacker Tools
- Underground Hacker Sites
- Hacking Tools Windows
- Pentest Reporting Tools
- Hacker Security Tools
- Hack Tools
- Hacking App
- Hak5 Tools
- Hacker Tools Hardware
- Hacking Tools Online
No comments:
Post a Comment