{"id":2150,"date":"2019-07-22T21:44:37","date_gmt":"2019-07-22T19:44:37","guid":{"rendered":"http:\/\/labalec.fr\/erwan\/?p=2150"},"modified":"2019-07-22T21:44:37","modified_gmt":"2019-07-22T19:44:37","slug":"runpe","status":"publish","type":"post","link":"https:\/\/labalec.fr\/erwan\/?p=2150","title":{"rendered":"RunPE"},"content":{"rendered":"<p>A demo to run a encrypted xored encrypted PE within the memory of another PE (and therefore possibly bypass anti virus softwares)<\/p>\n<p>See\u00a0<a href=\"https:\/\/github.com\/erwan2212\/XOR-freepascal\">https:\/\/github.com\/erwan2212\/XOR-freepascal<\/a>\u00a0about xoring \/ encrypting a file.<\/p>\n<p>Code is currently set to use cmd.exe (x86\/x64) as target host.<\/p>\n<p>host32.exe\/host64.exe are also provided in the zip if you wish the modify the code to use a \u00ab\u00a0neutral\u00a0\u00bb host.<\/p>\n<p>Source code and binaries can be found <a href=\"https:\/\/github.com\/erwan2212\/RunPE_XOR-freepascal\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A demo to run a encrypted xored encrypted PE within the memory of another PE (and therefore possibly bypass anti virus softwares) See\u00a0https:\/\/github.com\/erwan2212\/XOR-freepascal\u00a0about xoring \/ encrypting a file. Code is currently set to use cmd.exe (x86\/x64) as target host. host32.exe\/host64.exe are also provided in the zip if you wish the modify the code to use <a href='https:\/\/labalec.fr\/erwan\/?p=2150' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[113],"class_list":["post-2150","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-runpe","category-1-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"_links":{"self":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts\/2150","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2150"}],"version-history":[{"count":1,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts\/2150\/revisions"}],"predecessor-version":[{"id":2151,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=\/wp\/v2\/posts\/2150\/revisions\/2151"}],"wp:attachment":[{"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2150"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2150"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/labalec.fr\/erwan\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2150"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}