图片免杀
地址 https://github.com/Hangingsword/HouQing
修改key
![](https://upload-images.jianshu.io/upload_images/4664072-c38892f30e5bec80.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
生成shellcode
![](https://upload-images.jianshu.io/upload_images/4664072-66c9bccee67c8854.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
将生成的shellcode放入code.go
![](https://upload-images.jianshu.io/upload_images/4664072-6ce2f0cd44e96015.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
写入图片 go run code.go 11.jpeg
![](https://upload-images.jianshu.io/upload_images/4664072-c4e2368b56dc8fdf.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
将11.jpeg放入vps
执行命令 开启web服务
python -m SimpleHTTPServer 8000
![](https://upload-images.jianshu.io/upload_images/4664072-a6604331c1b6e4b4.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
修改loader.go
![](https://upload-images.jianshu.io/upload_images/4664072-9a6f1164916b212b.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
通过执行 go run loader.go 执行上线
![](https://upload-images.jianshu.io/upload_images/4664072-c7873ed9ed22ef0e.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
![](https://upload-images.jianshu.io/upload_images/4664072-245bc89051e265c7.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
此时上线成功
执行命令
go build -ldflags="-H windowsgui" Loader.go
编译为exe文件
![](https://upload-images.jianshu.io/upload_images/4664072-244f6c274573c384.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
绕过360 火绒静态动态查杀
![](https://upload-images.jianshu.io/upload_images/4664072-53788c73961616cb.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
成功上线
![](https://upload-images.jianshu.io/upload_images/4664072-2f0ec8b8d43cc8ef.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
设置自启动压缩文件
![](https://upload-images.jianshu.io/upload_images/4664072-dd3b1cf92bc2b934.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
设置为英文.exe
常规--选择 创建自解压格式压缩文件
选择高级--自解压选项--选择绝对路径 C:\Windows\Temp
选择设置--提取运行
C:\Windows\Temp\Loader.exe
C:\Windows\Temp\11.jpg
![](https://upload-images.jianshu.io/upload_images/4664072-08974684d5b0666f.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
选择模式--全部隐藏
![](https://upload-images.jianshu.io/upload_images/4664072-a9360087a7e1596a.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
选择更新--解压并更新文件--覆盖所有文件
![](https://upload-images.jianshu.io/upload_images/4664072-8e01c697f11ba895.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)
点击后生成gpj.exe
接下来使用文件名反转
在g名称前面右键,选择插入Unicode字符的RLO,修改后为 exe.jpg
![](https://upload-images.jianshu.io/upload_images/4664072-ac357280cb2de40c.png?imageMogr2/auto-orient/strip%7CimageView2/2/w/1240)