MCPcopy Create free account
hub / github.com/Maldev-Academy/ExecutePeFromPngViaLNK

github.com/Maldev-Academy/ExecutePeFromPngViaLNK @main

Chat with this repo
repository ↗ · DeepWiki ↗ · + Follow
20 symbols 56 edges 3 files 0 documented · 0% updated 22mo ago★ 4781 open issues

Browse by type

Functions 20 Types & classes 0
What it actually does AI analysis from the code graph — generated when you open this
loading…
README

ExecutePeFromPngViaLNK

Extract and execute a PE embedded within a PNG file using an LNK file. The PE file is encrypted using a single-key XOR algorithm and then injected as an IDAT section to the end of a specified PNG file.

Quick Links

Maldev Academy Home

Maldev Academy Syllabus

Maldev Academy Pricing

Usage

  1. Use InsertPeIntoPng.py to create the embedded PNG file and generate the extraction LNK file:

image

The generated LNK file will have the icon of a PDF file by default, and it will expect the embedded PNG file to be in the same directory when executed. PE files will be stored under the %TEMP% directory for execution.

image

Demo - Executing Dll

https://github.com/user-attachments/assets/adccab21-a05e-4f79-9590-b2ea4160ec4b

Demo - Executing Exe

https://github.com/user-attachments/assets/d47a0f3d-1689-4c57-bb1f-7559ad23ce04

Core symbols most depended-on inside this repo

browse all functions →

Shape

Function 20

Languages

Python85%
C15%

Modules by API surface

InsertPeIntoPng.py17 symbols
Test/HelloWorldDll/HelloWorldDll/DllMain.c2 symbols
Test/HelloWorld/HelloWorld/Main.c1 symbols

For agents

$ claude mcp add ExecutePeFromPngViaLNK \
  -- python -m otcore.mcp_server <graph>

⬇ download graph artifact

Ask about this repo answers extend the page