mirror of
https://github.com/2vg/blackcat-rs
synced 2026-06-08 10:16:29 +00:00
test: process-hide
This commit is contained in:
@@ -9,5 +9,6 @@ edition = "2018"
|
||||
[workspace]
|
||||
members = [
|
||||
"crate/payload-sample",
|
||||
"crate/process-hide",
|
||||
"crate/process-hollow",
|
||||
]
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
[package]
|
||||
name = "process-hide"
|
||||
version = "0.1.0"
|
||||
authors = ["m0fqn"]
|
||||
edition = "2018"
|
||||
|
||||
# See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html
|
||||
|
||||
[dependencies]
|
||||
anyhow = "1.0.38"
|
||||
detour = "0.7.1"
|
||||
minhook-sys = "0.1.1"
|
||||
ntapi = "0.3.6"
|
||||
winapi = { version = "0.3.9", features = ["libloaderapi", "minwindef"] }
|
||||
@@ -0,0 +1,96 @@
|
||||
use anyhow::*;
|
||||
use minhook_sys::*;
|
||||
use ntapi::ntexapi::{ NtQuerySystemInformation, SYSTEM_PROCESS_INFORMATION };
|
||||
use winapi::{
|
||||
shared::{
|
||||
minwindef::{ FARPROC },
|
||||
ntdef::{ HANDLE, LARGE_INTEGER, NTSTATUS, PULONG, PVOID, ULONG, UNICODE_STRING }
|
||||
},
|
||||
um::libloaderapi::{ GetModuleHandleA, GetProcAddress }
|
||||
};
|
||||
|
||||
use std::{ffi::CString, mem::{size_of, size_of_val}, ptr::null_mut};
|
||||
use std::mem::zeroed;
|
||||
|
||||
type SYSTEM_INFORMATION_CLASS = u32;
|
||||
|
||||
struct SYSTEM_PROCESS_INFO {
|
||||
NextEntryOffset: ULONG,
|
||||
NumberOfThreads: ULONG,
|
||||
Reserved: [LARGE_INTEGER; 3],
|
||||
CreateTime: LARGE_INTEGER,
|
||||
UserTime: LARGE_INTEGER,
|
||||
KernelTime: LARGE_INTEGER,
|
||||
ImageName: UNICODE_STRING,
|
||||
BasePriority: ULONG,
|
||||
ProcessId: HANDLE,
|
||||
InheritedFromProcessId: HANDLE
|
||||
}
|
||||
|
||||
unsafe fn detour_NtQuerySystemInformation(SystemInformationClass: SYSTEM_INFORMATION_CLASS, SystemInformation: PVOID, SystemInformationLength: ULONG, ReturnLength: PULONG) -> NTSTATUS {
|
||||
let p_current = zeroed::<SYSTEM_PROCESS_INFORMATION>();
|
||||
let p_next = zeroed::<SYSTEM_PROCESS_INFORMATION>();
|
||||
|
||||
let status = NtQuerySystemInformation(SystemInformationClass, SystemInformation, SystemInformationLength, ReturnLength);
|
||||
println!("debug");
|
||||
|
||||
if SystemInformationClass == 0x39 {
|
||||
let processes = std::slice::from_raw_parts::<SYSTEM_PROCESS_INFORMATION>(SystemInformation as *mut _, ((SystemInformationLength / std::mem::size_of::<SYSTEM_PROCESS_INFORMATION>() as u32)) as usize);
|
||||
|
||||
for process in processes {
|
||||
println!("process: {}", 1);
|
||||
}
|
||||
};
|
||||
|
||||
status
|
||||
}
|
||||
|
||||
pub fn hook_init() -> Result<()> {
|
||||
match unsafe { MH_Initialize() } {
|
||||
MH_OK => {
|
||||
println!("done hook init.");
|
||||
Ok(())
|
||||
},
|
||||
_ => { bail!("error on hook init process.") }
|
||||
}
|
||||
}
|
||||
|
||||
pub fn set_hook() -> Result<()> {
|
||||
let module = CString::new::<String>("ntdll.dll".into()).expect("CString::new failed");
|
||||
let api = CString::new::<String>("NtQuerySystemInformation".into()).expect("CString::new failed");
|
||||
|
||||
let hook_fn: FARPROC = detour_NtQuerySystemInformation as unsafe fn(SYSTEM_INFORMATION_CLASS, PVOID, ULONG, PULONG) -> NTSTATUS as _;
|
||||
let mut p_ntquery = unsafe { GetProcAddress(GetModuleHandleA(module.as_ptr() as *const _), api.as_ptr() as *const _) } ;
|
||||
let pp_ntquery: *mut FARPROC = &mut p_ntquery as _;
|
||||
|
||||
let status = unsafe { MH_CreateHookApi(e("ntdll.dll").as_ptr(), api.as_ptr(), hook_fn as _,pp_ntquery as _) };
|
||||
|
||||
match status {
|
||||
MH_OK => { },
|
||||
_ => { bail!("could not craete hook. error code: {}", status) }
|
||||
};
|
||||
|
||||
let status = unsafe { MH_EnableHook(hook_fn as _) };
|
||||
|
||||
match status {
|
||||
MH_OK => { },
|
||||
_ => { bail!("could not enable the hook. error code: {}", status) }
|
||||
};
|
||||
|
||||
// unsafe { test_call() };
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn e(source: &str) -> Vec<u16> {
|
||||
source.encode_utf16().chain(Some(0)).collect()
|
||||
}
|
||||
|
||||
unsafe fn test_call() {
|
||||
let sys_class = zeroed::<SYSTEM_INFORMATION_CLASS>();
|
||||
let mut buffer = zeroed::<[u8; 0xFF0000]>();
|
||||
|
||||
let status = NtQuerySystemInformation(sys_class, &mut buffer as *const _ as *mut _, 0x10000 as u32, std::ptr::null_mut()) as i64;
|
||||
|
||||
println!("call result: {}", status);
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
extern crate process_hide;
|
||||
|
||||
use anyhow::*;
|
||||
|
||||
fn main() -> Result<()> {
|
||||
process_hide::hook_init()?;
|
||||
process_hide::set_hook()?;
|
||||
std::thread::sleep(std::time::Duration::from_millis(30000000));
|
||||
Ok(())
|
||||
}
|
||||
Reference in New Issue
Block a user