Using x64dbg to reverse-confuse unmanaged shells

Source: Internet
Author: User

Systemdomain::executemainmethod the breakpoint, is a very eclectic solution, not too deep inside the CLR, will not casually be caught
When you run here, the main assembly has been restored to the corresponding location by these unmanaged shells
Why does this say, see

This is the call stack for the main thread (I ran the message pump in the main thread, so I paused)
You can see that the bottom is an unnamed address and it should be a shell like TMD.
Look up, there's a clr._corexemain and Clr._corexemaininternal,clr._corexemain is an export function

There is the risk of being hook, so the breakpoint here is not suitable, clr._corexemaininternal can actually, but not very good (not tested)
Then the
······
Clr. Runmain
Clr. Assembly::executemainmethod
Clr. Systemdomain::executemainmethod
Clr. Executeexe
······
These 4 should all be possible, are relatively safe, almost impossible to hook, direct dump at this time the main module is no problem
However, only the CLR was tested. Systemdomain::executemainmethod, tested 3 shells (2 strong shells, 1 packers), all available

Using x64dbg to reverse-confuse unmanaged shells

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.