oddcod3 / Phantom-Evasion

Python antivirus evasion tool
GNU General Public License v3.0
1.39k stars 335 forks source link

VirtualAlloc NoDirectCall LL/GPA crashes on latest version #31

Closed phra closed 6 years ago

phra commented 6 years ago

steps to reproduce:

  1. Windows Modules
  2. Windows Shellcode Injection VirtualAlloc NoDirectCall LL/GPA
  3. Payload: windows/x64/meterpreter/reverse_https
  4. Encoder: x64/xor + Triple Multibyte-key xor
  5. Add multiple processes behaviour? y, 3

result:

image

oddcod3 commented 6 years ago

Thank you @phra the issue (two missing brackets) has been solved!

phra commented 6 years ago

fixed via https://github.com/oddcod3/Phantom-Evasion/commit/e20261415ac8e16335198155bf91d82547e8158a