EQGRP_Lost_in_Translation
EQGRP_Lost_in_Translation copied to clipboard
what is "DOPU shellcode buffer"
how to set up the value of "DOPU shellcode buffer"
use Eternalchampion
-
https://github.com/boogaloo1977/EquationGroup/blob/2364f4bf3fb73f1d467fdcc8285742eaad2db86e/windows/payloads/Doublepulsar-1.3.1.0.xml#L71
-
https://github.com/boogaloo1977/EquationGroup/blob/2364f4bf3fb73f1d467fdcc8285742eaad2db86e/windows/specials/Eternalchampion-2.0.0.0.xml#L25
https://github.com/misterch0c/shadowbroker/issues/20
shellcode buffer
means you need to use DoublePulsar to generate a shellcode(about 4KiB) and paste its hex content to fb(you could use WinHex
to copy its hex), while shellcode file
needs that 4KiB file generated by DoublePulsar in which you only need to point out its path.
Judging by your bio, I assume you would probably understand Chinese so you could go to my profile page and check it out on my blogsite.