From 9ec8d7e7f74dc15b2b621fb38f3dce113a40e92e Mon Sep 17 00:00:00 2001 From: senzee <33692631+senzee1984@users.noreply.github.com> Date: Thu, 11 Jan 2024 19:01:31 -0500 Subject: [PATCH] Add files via upload --- ReadPEInMemory.cpp | 184 +++++++++++++++++++++++++++++++++ ReadPEInMemory.sln | 31 ++++++ ReadPEInMemory.vcxproj | 135 ++++++++++++++++++++++++ ReadPEInMemory.vcxproj.filters | 22 ++++ ReadPEInMemory.vcxproj.user | 4 + 5 files changed, 376 insertions(+) create mode 100644 ReadPEInMemory.cpp create mode 100644 ReadPEInMemory.sln create mode 100644 ReadPEInMemory.vcxproj create mode 100644 ReadPEInMemory.vcxproj.filters create mode 100644 ReadPEInMemory.vcxproj.user diff --git a/ReadPEInMemory.cpp b/ReadPEInMemory.cpp new file mode 100644 index 0000000..07e404f --- /dev/null +++ b/ReadPEInMemory.cpp @@ -0,0 +1,184 @@ + + +#include +#include +#include + + +#pragma comment(lib, "ntdll.lib") +#pragma warning(disable:4996) + +EXTERN_C NTSTATUS NTAPI NtQueryInformationProcess( + HANDLE ProcessHandle, + PROCESSINFOCLASS ProcessInformationClass, + PVOID ProcessInformation, + ULONG ProcessInformationLength, + PULONG ReturnLength +); + + +BOOL ReadPeFile(LPCSTR lpFileName, PBYTE* pPe, SIZE_T* sPe) { + + HANDLE hFile = INVALID_HANDLE_VALUE; + PBYTE pBuff = NULL; + DWORD dwFileSize = NULL, + dwNumberOfBytesRead = NULL; + + hFile = CreateFileA(lpFileName, GENERIC_READ, 0, NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL); + if (hFile == INVALID_HANDLE_VALUE) { + printf("[!] CreateFileA Failed With Error : %d \n", GetLastError()); + goto _EndOfFunction; + } + + dwFileSize = GetFileSize(hFile, NULL); + if (dwFileSize == NULL) { + printf("[!] GetFileSize Failed With Error : %d \n", GetLastError()); + goto _EndOfFunction; + } + + pBuff = (PBYTE)HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, dwFileSize); + if (pBuff == NULL) { + printf("[!] HeapAlloc Failed With Error : %d \n", GetLastError()); + goto _EndOfFunction; + } + + if (!ReadFile(hFile, pBuff, dwFileSize, &dwNumberOfBytesRead, NULL) || dwFileSize != dwNumberOfBytesRead) { + printf("[!] ReadFile Failed With Error : %d \n", GetLastError()); + printf("[!] Bytes Read : %d of : %d \n", dwNumberOfBytesRead, dwFileSize); + goto _EndOfFunction; + } + + printf("[+] DONE \n"); + + +_EndOfFunction: + *pPe = (PBYTE)pBuff; + *sPe = (SIZE_T)dwFileSize; + if (hFile) + CloseHandle(hFile); + if (*pPe == NULL || *sPe == NULL) + return FALSE; + return TRUE; +} + + + +DWORD ParsePe(PBYTE pPE) +{ + DWORD size = 0; + PIMAGE_DOS_HEADER pImgDosHdr = (PIMAGE_DOS_HEADER)pPE; + if (pImgDosHdr->e_magic != IMAGE_DOS_SIGNATURE) { + return -1; + } + + PIMAGE_NT_HEADERS pImgNtHdrs = (PIMAGE_NT_HEADERS)(pPE + pImgDosHdr->e_lfanew); + if (pImgNtHdrs->Signature != IMAGE_NT_SIGNATURE) { + return -1; + } + + IMAGE_FILE_HEADER ImgFileHdr = pImgNtHdrs->FileHeader; + + IMAGE_OPTIONAL_HEADER ImgOptHdr = pImgNtHdrs->OptionalHeader; + if (ImgOptHdr.Magic != IMAGE_NT_OPTIONAL_HDR_MAGIC) { + return -1; + } + + printf("[+] Size Of The Image : 0x%x \n", ImgOptHdr.SizeOfImage); + size = ImgOptHdr.SizeOfImage; + return size; +} + + + + + +int main(int argc, char* argv[]) +{ + + PBYTE pPE = NULL; + SIZE_T sPE = NULL; + if (argc < 3) + { + printf("Usage: ReadPEInMemoryMemory.exe input output\nE.g. ReadPEInMemory.exe calc.exe calc.bin\n"); + return -1; + } + LPCSTR filename = argv[1]; + char* outputbin = argv[2]; + if (!ReadPeFile(filename, &pPE, &sPE)) { + return -1; + } + + DWORD size_of_image = ParsePe(pPE); + HeapFree(GetProcessHeap(), NULL, pPE); + + STARTUPINFOA si; + PROCESS_INFORMATION pi; + ZeroMemory(&si, sizeof(si)); + si.cb = sizeof(si); + ZeroMemory(&pi, sizeof(pi)); + + if (!CreateProcessA(filename, NULL, NULL, NULL, FALSE, 0, NULL, NULL, &si, &pi)) { + printf("CreateProcess failed (%d).\n", GetLastError()); + return 1; + } + printf("Process PID: %lu\n", pi.dwProcessId); + PROCESS_BASIC_INFORMATION pbi; + NTSTATUS status = NtQueryInformationProcess(pi.hProcess, ProcessBasicInformation, &pbi, sizeof(PROCESS_BASIC_INFORMATION), NULL); + + if (status == 0) { + printf("PEB Address:%p\n", pbi.PebBaseAddress); + PVOID imageBaseAddress; + SIZE_T bytesRead; + + ReadProcessMemory(pi.hProcess, (PCHAR)pbi.PebBaseAddress + sizeof(PVOID) * 2, &imageBaseAddress, sizeof(PVOID), &bytesRead); + printf("Image Base Address:%p\n", imageBaseAddress); + + SIZE_T totalSize = size_of_image; //Total size of PE image in memory + const SIZE_T CHUNK_SIZE = 0xb000; // Chunk size for reading and writing + BYTE buffer[0xb000]; //Number of bytes read each time + + + //SIZE_T bytesRead = 0; + SIZE_T totalBytesRead = 0; + + // Calculate the number of iterations needed + int numIterations = (totalSize / CHUNK_SIZE) + (totalSize % CHUNK_SIZE ? 1 : 0); + + FILE* file = fopen(outputbin, "ab"); // Open file in append mode + if (file == NULL) { + printf("Failed to open %s for writing\n",outputbin); + exit(1); + } + + for (int iteration = 0; iteration < numIterations; iteration++) { + BYTE buffer[CHUNK_SIZE]; + SIZE_T offset = iteration * CHUNK_SIZE; + SIZE_T sizeToRead = min(CHUNK_SIZE, totalSize - offset); + + if (!ReadProcessMemory(pi.hProcess, (PBYTE)imageBaseAddress + offset, &buffer, sizeToRead, &bytesRead)) { + // Handle read error + printf("Error reading memory: %d\n", GetLastError()); + break; + } + + fwrite(buffer, 1, bytesRead, file); // Write the chunk to the file + totalBytesRead += bytesRead; + + // Print each byte (optional, for debugging) + /*for (int i = 0; i < bytesRead; i++) { + // ... Your existing printing logic ... + }*/ + } + + // Clean up + fclose(file); + printf("Data successfully written to %s. Total bytes read: 0x%x\n", outputbin,totalBytesRead); + } + else { + printf("Error"); + } + + CloseHandle(pi.hProcess); + CloseHandle(pi.hThread); + return 0; +} diff --git a/ReadPEInMemory.sln b/ReadPEInMemory.sln new file mode 100644 index 0000000..fd1c5ac --- /dev/null +++ b/ReadPEInMemory.sln @@ -0,0 +1,31 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio Version 17 +VisualStudioVersion = 17.8.34316.72 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "ReadPEInMemory", "ReadPEInMemory.vcxproj", "{6727C860-156A-41B5-97F1-A81D73B9B830}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|x64 = Debug|x64 + Debug|x86 = Debug|x86 + Release|x64 = Release|x64 + Release|x86 = Release|x86 + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {6727C860-156A-41B5-97F1-A81D73B9B830}.Debug|x64.ActiveCfg = Debug|x64 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Debug|x64.Build.0 = Debug|x64 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Debug|x86.ActiveCfg = Debug|Win32 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Debug|x86.Build.0 = Debug|Win32 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Release|x64.ActiveCfg = Release|x64 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Release|x64.Build.0 = Release|x64 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Release|x86.ActiveCfg = Release|Win32 + {6727C860-156A-41B5-97F1-A81D73B9B830}.Release|x86.Build.0 = Release|Win32 + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {575FDC66-9870-42D5-B4CA-F3711C0F1880} + EndGlobalSection +EndGlobal diff --git a/ReadPEInMemory.vcxproj b/ReadPEInMemory.vcxproj new file mode 100644 index 0000000..1e96a27 --- /dev/null +++ b/ReadPEInMemory.vcxproj @@ -0,0 +1,135 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 17.0 + Win32Proj + {6727c860-156a-41b5-97f1-a81d73b9b830} + ReadPEInMemory + 10.0 + + + + Application + true + v143 + Unicode + + + Application + false + v143 + true + Unicode + + + Application + true + v143 + Unicode + + + Application + false + v143 + true + Unicode + + + + + + + + + + + + + + + + + + + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + \ No newline at end of file diff --git a/ReadPEInMemory.vcxproj.filters b/ReadPEInMemory.vcxproj.filters new file mode 100644 index 0000000..4429723 --- /dev/null +++ b/ReadPEInMemory.vcxproj.filters @@ -0,0 +1,22 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;c++;cppm;ixx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + \ No newline at end of file diff --git a/ReadPEInMemory.vcxproj.user b/ReadPEInMemory.vcxproj.user new file mode 100644 index 0000000..0f14913 --- /dev/null +++ b/ReadPEInMemory.vcxproj.user @@ -0,0 +1,4 @@ + + + + \ No newline at end of file