本文へ移動
cccskills
無料GitHub で公開

recovering-injected-code-and-shellcode

Carves injected PE images and position-independent shellcode from a memory dump or carved region, identifies the payload type, and prepares it for disassembly or emulation. Activates for requests to recover injected code, carve shellcode from memory, or reconstruct a dumped payload for analysis.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md2.8 KB
  • LICENSE340 B
  • references/api-reference.md1.2 KB
  • scripts/analyst.py2.3 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Recovering Injected Code and Shellcode

When to Use

  • You have a carved memory region (from malfind/vaddump) and need to identify and extract the payload — an injected PE or raw shellcode.
  • You need to locate likely shellcode entry points (egg hunters, GetPC stubs) before disassembly.

Do not use this to execute the payload — it prepares code for static disassembly/emulation in a controlled tool, not for running.

Prerequisites

  • A carved binary region (raw bytes) from a memory image.

Safety & Handling

  • The carved region is live malicious code; store it password-protected and never execute it.

Workflow

Step 1: Identify payload type

python scripts/analyst.py identify region.bin

Detects an embedded MZ/PE (with offset) versus raw shellcode, and reports the PE's architecture if present.

Step 2: Locate shellcode entry hints

Finds common position-independent code markers: GetPC stubs (call $+5/fldz/fnstenv), PEB access (fs:[30]/gs:[60]), and API-hashing loops.

Step 3: Extract for analysis

Carve the PE at its offset (or keep the raw shellcode) and hand it to a disassembler/emulator at the detected base/entry.

Step 4: Document

Record offsets, architecture, and entry hints for the downstream RE workflow.

Validation

  • An embedded PE is confirmed by MZ + valid e_lfanew → PE\0\0.
  • Shellcode entry hints reference real PIC patterns, not arbitrary bytes.
  • Architecture detection matches the PE Machine field (or PIC heuristics for raw shellcode).

Pitfalls

  • Assuming everything carved is a PE; much injected code is headerless shellcode.
  • Wrong base address breaking relocations when loading a dumped PE — note it for rebuilding.
  • Treating compressed/encrypted stages as final shellcode without a decode pass.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する