Added CRC32 seed value for randomizing the API hashes.

This commit is contained in:
Ege Balcı
2023-05-19 14:38:22 +02:00
parent 14a7f8b5eb
commit d77aa9d148
3 changed files with 12 additions and 4 deletions
+5 -2
View File
@@ -2,7 +2,7 @@
; Author: Ege Balcı (egebalci[at]pm[dot]me)
; Version: 1.1 (29 April 2023)
; Architecture: x64
; Size: 186 bytes
; Size: 192 bytes
;-----------------------------------------------------------------------------;
[BITS 64]
@@ -13,9 +13,11 @@
; Input: The CRC32 hash of the module and function name.
; Output: The address of the function will be in RAX.
; Clobbers: R10
; Un-Clobbered: RAX, RCX, RDX, R8, R9, RBX, RSI, RDI, RBP, R12, R13, R14, R15.
; Un-Clobbered: RCX, RDX, R8, R9, RBX, RSI, RDI, RBP, R12, R13, R14, R15.
; Note: This function assumes the direction flag has allready been cleared via a CLD instruction.
%define CRC32_SEED 0x00
api_call:
push r9 ; Save R9
push r8 ; Save R8
@@ -30,6 +32,7 @@ next_mod: ;
mov rsi, [rdx+80] ; Get pointer to modules name (unicode string)
movzx rcx, word [rdx+74] ; Set rcx to the length we want to check
xor r9, r9 ; Clear r9 which will store the hash of the module name
mov r9, CRC32_SEED ; Set the initial CRC32 seed value
loop_modname: ;
xor rax, rax ; Clear RAX
lodsb ; Read in the next byte of the name
+4 -1
View File
@@ -2,7 +2,7 @@
; Author: Ege Balcı (egebalci[at]pm[dot]me)
; Version: 1.1 (29 April 2023)
; Architecture: x86
; Size: 124 bytes
; Size: 129 bytes
;-----------------------------------------------------------------------------;
[BITS 32]
@@ -13,6 +13,8 @@
; Un-Clobbered: EBX, ESI, EDI, ESP and EBP can be expected to remain un-clobbered.
; Note: This function assumes the direction flag has allready been cleared via a CLD instruction.
%define CRC32_SEED 0x00
api_call:
pushad ; We preserve all the registers for the caller, bar EAX and ECX.
mov ebp, esp ; Create a new stack frame
@@ -24,6 +26,7 @@ next_mod: ;
mov esi, [edx+40] ; Get pointer to modules name (unicode string)
movzx ecx, word [edx+38] ; Set ECX to the length we want to check
xor edi, edi ; Clear EDI which will store the hash of the module name
mov edi, CRC32_SEED ; Set the initial CRC32 seed value
loop_modname: ;
lodsb ; Read in the next byte of the name
cmp al, 'a' ; Some versions of Windows use lower case module names
+3 -1
View File
@@ -9,6 +9,8 @@
from sys import path
import os, time, sys, crcmod
CRC32_SEED=0
def unicode( string, uppercase=True ):
result = "";
if uppercase:
@@ -18,7 +20,7 @@ def unicode( string, uppercase=True ):
return result
#=============================================================================#
def hash( module, function, bits=13, print_hash=True ):
crc32_func = crcmod.mkCrcFun(0x11EDC6F41, initCrc=0, xorOut=0)
crc32_func = crcmod.mkCrcFun(0x11EDC6F41, initCrc=CRC32_SEED, xorOut=0)
h = crc32_func((unicode(module)+function+"\x00").encode('utf-8'))
print("[+] 0x%08X = %s!%s" % ( h, module.lower(), function ))
return h