embee-research / Randomise-api-hashes-cobalt-strike

Bypass Detection By Randomising ROR13 API Hashes
131 stars 14 forks source link

x86 shellcode crashed #1

Open GG-o1 opened 2 years ago

GG-o1 commented 2 years ago

payload.bin: cobaltstrike 4.4 x86 shellcode(stager) , which already replaced apihash by this tool. And when I use blobrunner(x86) to load it , crashed

image
embee-research commented 2 years ago

@GG-o1 Are you able to provide a copy of the shellcode before or after the script? If so, I can take a look into this for you.