mirror of
https://github.com/2vg/blackcat-rs
synced 2026-06-08 10:16:29 +00:00
remove reflective-dll-injection
This commit is contained in:
@@ -14,7 +14,6 @@ members = [
|
||||
"crate/payload-sample",
|
||||
"crate/process-hide",
|
||||
"crate/process-hollow",
|
||||
"crate/reflective-dll-injection",
|
||||
"crate/wuhu",
|
||||
"crate/yura",
|
||||
]
|
||||
|
||||
@@ -1,18 +0,0 @@
|
||||
[package]
|
||||
name = "reflective-dll-injection"
|
||||
version = "0.1.0"
|
||||
authors = ["uru <mail@nyaa.gg>"]
|
||||
edition = "2018"
|
||||
|
||||
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
||||
|
||||
[dependencies]
|
||||
pe-tools = { path = "../pe-tools" }
|
||||
winapi = { version = "0.3.9", features = ["winuser"] }
|
||||
ntapi = { version = "0.3.6", features = ["nightly"] }
|
||||
anyhow = "1.0.39"
|
||||
pelite = "0.9.0"
|
||||
|
||||
[lib]
|
||||
name = "dll64"
|
||||
crate-type = ["cdylib"]
|
||||
@@ -1,34 +0,0 @@
|
||||
use crate::dll::loader64;
|
||||
use winapi::shared::minwindef::{BOOL, DWORD, HINSTANCE, LPVOID};
|
||||
|
||||
#[no_mangle]
|
||||
#[allow(non_snake_case)]
|
||||
pub unsafe extern "system" fn DllMain(
|
||||
_module: HINSTANCE,
|
||||
call_reason: DWORD,
|
||||
_reserved: LPVOID,
|
||||
) -> BOOL {
|
||||
match call_reason {
|
||||
DLL_PROCESS_ATTACH => {
|
||||
msg("hello", "test");
|
||||
}
|
||||
_ => {}
|
||||
};
|
||||
|
||||
true as _
|
||||
}
|
||||
|
||||
use std::ptr;
|
||||
use winapi::um::winuser::{MessageBoxW, MB_OK};
|
||||
|
||||
fn e(source: &str) -> Vec<u16> {
|
||||
source.encode_utf16().chain(Some(0)).collect()
|
||||
}
|
||||
|
||||
fn msg(t: impl Into<String>, c: impl Into<String>) {
|
||||
let t = t.into();
|
||||
let c = c.into();
|
||||
unsafe {
|
||||
MessageBoxW(ptr::null_mut(), e(&c).as_ptr(), e(&t).as_ptr(), MB_OK);
|
||||
}
|
||||
}
|
||||
@@ -1,125 +0,0 @@
|
||||
#[allow(non_snake_case)]
|
||||
#[allow(non_camel_case_types)]
|
||||
extern crate pe_tools;
|
||||
|
||||
use std::ptr::null_mut;
|
||||
|
||||
use anyhow::*;
|
||||
use ntapi::{ntpebteb::PEB, winapi_local::um::winnt::__readgsqword};
|
||||
use pe_tools::shared::*;
|
||||
use pe_tools::x64::*;
|
||||
use winapi::{
|
||||
shared::{
|
||||
basetsd::SIZE_T,
|
||||
minwindef::{BOOL, DWORD, HINSTANCE, LPVOID},
|
||||
ntdef::{HANDLE, NTSTATUS, PVOID},
|
||||
},
|
||||
um::winnt::{
|
||||
DLL_PROCESS_ATTACH, MEM_COMMIT, MEM_RESERVE, PAGE_EXECUTE_READWRITE, PAGE_READWRITE,
|
||||
},
|
||||
};
|
||||
|
||||
pub type PVirtualAlloc =
|
||||
fn(lpAddress: LPVOID, dwSize: SIZE_T, flAllocationType: DWORD, flProtect: DWORD) -> LPVOID;
|
||||
pub type PNtFlushInstructionCache =
|
||||
fn(ProcessHandle: HANDLE, BaseAddress: PVOID, Length: SIZE_T) -> NTSTATUS;
|
||||
pub type DllMain = unsafe extern "system" fn(HINSTANCE, DWORD, LPVOID) -> BOOL;
|
||||
|
||||
#[no_mangle]
|
||||
pub extern "system" fn reflective_load() -> bool {
|
||||
match __reflective_load() {
|
||||
Ok(_) => true,
|
||||
Err(_) => false,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn __reflective_load() -> Result<()> {
|
||||
unsafe {
|
||||
// 1: get image base address of own, create pe container
|
||||
let ppeb = __readgsqword(0x60) as *mut PEB;
|
||||
let my_base_address = (*ppeb).ImageBaseAddress;
|
||||
let mut container = PEContainer::new(my_base_address, true)?;
|
||||
|
||||
// 2: get address needed by the loading process
|
||||
let pLoadLibraryA =
|
||||
ptr_to_fn::<PLoadLibraryA>(search_proc_address_from_loaded_module("LoadLibraryA")?);
|
||||
let pGetProcAddress =
|
||||
ptr_to_fn::<PGetProcAddress>(search_proc_address_from_loaded_module("GetProcAddress")?);
|
||||
let pVirtualAlloc =
|
||||
ptr_to_fn::<PVirtualAlloc>(search_proc_address_from_loaded_module("VirtualAlloc")?);
|
||||
let pNtFlushInstructionCache = ptr_to_fn::<PNtFlushInstructionCache>(
|
||||
search_proc_address_from_loaded_module("NtFlushInstructionCache")?,
|
||||
);
|
||||
|
||||
// 3: allocate new v memory, and change target base address to it
|
||||
let mut allocated = pVirtualAlloc(
|
||||
container.image_base_address(),
|
||||
container.image_size() as _,
|
||||
MEM_RESERVE | MEM_COMMIT,
|
||||
PAGE_READWRITE,
|
||||
);
|
||||
|
||||
if allocated as u64 == 0x0 as u64 {
|
||||
allocated = pVirtualAlloc(
|
||||
null_mut(),
|
||||
container.image_size() as _,
|
||||
MEM_RESERVE | MEM_COMMIT,
|
||||
PAGE_READWRITE,
|
||||
);
|
||||
};
|
||||
|
||||
if allocated as u64 == 0x0 as u64 {
|
||||
bail!(
|
||||
"could not allocate of the remote process image. VirtualAlloc calling was failed."
|
||||
)
|
||||
};
|
||||
|
||||
// 4: copy over headers
|
||||
container.copy_headers_to(allocated)?;
|
||||
|
||||
// 5: copy over section headers
|
||||
container.copy_section_headers_to(allocated)?;
|
||||
|
||||
// 6: relocate it if needed.(this is need in almost case)
|
||||
container.delta_relocation(allocated)?;
|
||||
|
||||
// 7: resolve import table
|
||||
container.resolve_import(allocated, pLoadLibraryA, pGetProcAddress)?;
|
||||
|
||||
// TODO: 8: resolve delayed import?
|
||||
|
||||
// TODO: 9: call protect memory?
|
||||
|
||||
// 10: flush the instruction cache to avoid stale code being used
|
||||
pNtFlushInstructionCache(-1 as _, null_mut(), 0);
|
||||
|
||||
// 11: execute tls callbacks
|
||||
container.exec_tls_callback(allocated)?;
|
||||
|
||||
// TODO: 12: register exception handler?
|
||||
|
||||
// 13: call DllMain
|
||||
let p_dll_main = allocated as u64 + container.pe.entry as u64;
|
||||
let dll_main = ptr_to_fn::<DllMain>(p_dll_main as _);
|
||||
|
||||
dll_main(allocated as _, DLL_PROCESS_ATTACH, 1 as _);
|
||||
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
// for debug
|
||||
use std::ptr;
|
||||
use winapi::um::winuser::{MessageBoxW, MB_OK};
|
||||
|
||||
fn e(source: &str) -> Vec<u16> {
|
||||
source.encode_utf16().chain(Some(0)).collect()
|
||||
}
|
||||
|
||||
fn debug(t: impl Into<String>, c: impl Into<String>) {
|
||||
let t = t.into();
|
||||
let c = c.into();
|
||||
unsafe {
|
||||
MessageBoxW(ptr::null_mut(), e(&c).as_ptr(), e(&t).as_ptr(), MB_OK);
|
||||
}
|
||||
}
|
||||
@@ -1,2 +0,0 @@
|
||||
pub mod dll64;
|
||||
pub mod loader64;
|
||||
@@ -1,4 +0,0 @@
|
||||
extern crate pe_tools;
|
||||
|
||||
pub mod x64;
|
||||
pub mod x86;
|
||||
@@ -1,17 +0,0 @@
|
||||
use std::ptr::null_mut;
|
||||
|
||||
use anyhow::*;
|
||||
use pe_tools::{shared, x64};
|
||||
use pelite::pe64::exports::GetProcAddress;
|
||||
use winapi::ctypes::c_void;
|
||||
|
||||
pub fn get_loader_offset(dll_base_address: *mut c_void) -> Result<*mut c_void> {
|
||||
let dll_container = x64::PEContainer::new(dll_base_address, true)?;
|
||||
let loader = dll_container.search_expoted_func("reflective_load");
|
||||
|
||||
if loader.is_ok() {
|
||||
Ok(loader.unwrap() as _)
|
||||
} else {
|
||||
bail!("could not find reflective_load function")
|
||||
}
|
||||
}
|
||||
@@ -1 +0,0 @@
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
pub mod dll;
|
||||
pub mod inject;
|
||||
Reference in New Issue
Block a user