From bbc120295f99a4ab00f9cbb88655ee2cab6dcabe Mon Sep 17 00:00:00 2001 From: Winslow <33692631+senzee1984@users.noreply.github.com> Date: Fri, 16 Feb 2024 15:53:06 -0500 Subject: [PATCH] Add files via upload --- DumpPEFromMemory/DumpPEFromMemory.cpp | 171 ++++++++++++++++++ DumpPEFromMemory/DumpPEFromMemory.sln | 31 ++++ DumpPEFromMemory/DumpPEFromMemory.vcxproj | 135 ++++++++++++++ .../DumpPEFromMemory.vcxproj.filters | 22 +++ .../DumpPEFromMemory.vcxproj.user | 4 + 5 files changed, 363 insertions(+) create mode 100644 DumpPEFromMemory/DumpPEFromMemory.cpp create mode 100644 DumpPEFromMemory/DumpPEFromMemory.sln create mode 100644 DumpPEFromMemory/DumpPEFromMemory.vcxproj create mode 100644 DumpPEFromMemory/DumpPEFromMemory.vcxproj.filters create mode 100644 DumpPEFromMemory/DumpPEFromMemory.vcxproj.user diff --git a/DumpPEFromMemory/DumpPEFromMemory.cpp b/DumpPEFromMemory/DumpPEFromMemory.cpp new file mode 100644 index 0000000..e58c157 --- /dev/null +++ b/DumpPEFromMemory/DumpPEFromMemory.cpp @@ -0,0 +1,171 @@ +#include +#include +#include + + +#pragma comment(lib, "ntdll.lib") +#pragma warning(disable:4996) + +EXTERN_C NTSTATUS NTAPI NtQueryInformationProcess( + HANDLE ProcessHandle, + PROCESSINFOCLASS ProcessInformationClass, + PVOID ProcessInformation, + ULONG ProcessInformationLength, + PULONG ReturnLength +); + + +BOOL ReadPEFile(LPCSTR lpFileName, PBYTE* pPe, SIZE_T* sPe) { + + HANDLE hFile = INVALID_HANDLE_VALUE; + PBYTE pBuff = NULL; + DWORD dwFileSize = NULL, + dwNumberOfBytesRead = NULL; + + hFile = CreateFileA(lpFileName, GENERIC_READ, 0, NULL, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, NULL); + if (hFile == INVALID_HANDLE_VALUE) { + printf("[!] CreateFileA Failed With Error : %d \n", GetLastError()); + goto _EndOfFunction; + } + + dwFileSize = GetFileSize(hFile, NULL); + if (dwFileSize == NULL) { + printf("[!] GetFileSize Failed With Error : %d \n", GetLastError()); + goto _EndOfFunction; + } + + pBuff = (PBYTE)HeapAlloc(GetProcessHeap(), HEAP_ZERO_MEMORY, dwFileSize); + if (pBuff == NULL) { + printf("[!] HeapAlloc Failed With Error : %d \n", GetLastError()); + goto _EndOfFunction; + } + + if (!ReadFile(hFile, pBuff, dwFileSize, &dwNumberOfBytesRead, NULL) || dwFileSize != dwNumberOfBytesRead) { + printf("[!] ReadFile Failed With Error : %d \n", GetLastError()); + printf("[!] Bytes Read : %d of : %d \n", dwNumberOfBytesRead, dwFileSize); + goto _EndOfFunction; + } + + printf("[+] DONE \n"); + + +_EndOfFunction: + *pPe = (PBYTE)pBuff; + *sPe = (SIZE_T)dwFileSize; + if (hFile) + CloseHandle(hFile); + if (*pPe == NULL || *sPe == NULL) + return FALSE; + return TRUE; +} + + + +DWORD ParsePE(PBYTE pPE) +{ + DWORD size = 0; + PIMAGE_DOS_HEADER pImgDosHdr = (PIMAGE_DOS_HEADER)pPE; + if (pImgDosHdr->e_magic != IMAGE_DOS_SIGNATURE) { + return -1; + } + + PIMAGE_NT_HEADERS pImgNtHdrs = (PIMAGE_NT_HEADERS)(pPE + pImgDosHdr->e_lfanew); + if (pImgNtHdrs->Signature != IMAGE_NT_SIGNATURE) { + return -1; + } + + IMAGE_OPTIONAL_HEADER ImgOptHdr = pImgNtHdrs->OptionalHeader; + if (ImgOptHdr.Magic != IMAGE_NT_OPTIONAL_HDR_MAGIC) { + return -1; + } + + printf("[+] Size Of The Image : 0x%x \n", ImgOptHdr.SizeOfImage); + size = ImgOptHdr.SizeOfImage; + return size; +} + + + + + +int main(int argc, char* argv[]) +{ + PBYTE pPE = NULL; + SIZE_T sPE = NULL; + if (argc < 3) + { + printf("Usage: DumpPEFromMemoryMemory.exe \nE.g. ReadPEInMemory.exe mimikatz.exe mimikatz.bin\n"); + return -1; + } + LPCSTR filename = argv[1]; + char* outputbin = argv[2]; + + if (!ReadPEFile(filename, &pPE, &sPE)) { + return -1; + } + + DWORD size_of_image = ParsePE(pPE); + HeapFree(GetProcessHeap(), NULL, pPE); + + STARTUPINFOA si; + PROCESS_INFORMATION pi; + ZeroMemory(&si, sizeof(si)); + si.cb = sizeof(si); + ZeroMemory(&pi, sizeof(pi)); + + if (!CreateProcessA(filename, NULL, NULL, NULL, FALSE, CREATE_SUSPENDED, NULL, NULL, &si, &pi)) { + printf("CreateProcess failed (%d).\n", GetLastError()); + return 1; + } + printf("Process PID: %lu\n", pi.dwProcessId); + PROCESS_BASIC_INFORMATION pbi; + NTSTATUS status = NtQueryInformationProcess(pi.hProcess, ProcessBasicInformation, &pbi, sizeof(PROCESS_BASIC_INFORMATION), NULL); + + if (status == 0) { + printf("PEB Address:%p\n", pbi.PebBaseAddress); + PVOID imageBaseAddress; + SIZE_T bytesRead; + + ReadProcessMemory(pi.hProcess, (PCHAR)pbi.PebBaseAddress + sizeof(PVOID) * 2, &imageBaseAddress, sizeof(PVOID), &bytesRead); + printf("Image Base Address:%p\n", imageBaseAddress); + + SIZE_T totalSize = size_of_image; //Total size of PE image in memory + const SIZE_T CHUNK_SIZE = 0xb000; // Chunk size for reading and writing + BYTE buffer[0xb000]; //Number of bytes read each time + + + SIZE_T totalBytesRead = 0; + + // Calculate the number of iterations needed + int numIterations = (totalSize / CHUNK_SIZE) + (totalSize % CHUNK_SIZE ? 1 : 0); + + FILE* file = fopen(outputbin, "ab"); // Open file in append mode + if (file == NULL) { + printf("Failed to open %s for writing\n", outputbin); + exit(1); + } + + for (int iteration = 0; iteration < numIterations; iteration++) { + BYTE buffer[CHUNK_SIZE]; + SIZE_T offset = iteration * CHUNK_SIZE; + SIZE_T sizeToRead = min(CHUNK_SIZE, totalSize - offset); + + if (!ReadProcessMemory(pi.hProcess, (PBYTE)imageBaseAddress + offset, &buffer, sizeToRead, &bytesRead)) { + printf("Error reading memory: %d\n", GetLastError()); + break; + } + + fwrite(buffer, 1, bytesRead, file); + totalBytesRead += bytesRead; + } + + fclose(file); + printf("Data successfully written to %s. Total bytes read: 0x%x\n", outputbin, totalBytesRead); + } + else { + printf("Error"); + } + + TerminateProcess(pi.hProcess, 0); + return 0; +} diff --git a/DumpPEFromMemory/DumpPEFromMemory.sln b/DumpPEFromMemory/DumpPEFromMemory.sln new file mode 100644 index 0000000..93a8ccf --- /dev/null +++ b/DumpPEFromMemory/DumpPEFromMemory.sln @@ -0,0 +1,31 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio Version 17 +VisualStudioVersion = 17.8.34316.72 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "DumpPEFromMemory", "DumpPEFromMemory.vcxproj", "{EEC48565-5B42-491A-8BBB-16AC0C40C367}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|x64 = Debug|x64 + Debug|x86 = Debug|x86 + Release|x64 = Release|x64 + Release|x86 = Release|x86 + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Debug|x64.ActiveCfg = Debug|x64 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Debug|x64.Build.0 = Debug|x64 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Debug|x86.ActiveCfg = Debug|Win32 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Debug|x86.Build.0 = Debug|Win32 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Release|x64.ActiveCfg = Release|x64 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Release|x64.Build.0 = Release|x64 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Release|x86.ActiveCfg = Release|Win32 + {EEC48565-5B42-491A-8BBB-16AC0C40C367}.Release|x86.Build.0 = Release|Win32 + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {D8D49BE0-3374-4603-89EF-DD57D45AC8C5} + EndGlobalSection +EndGlobal diff --git a/DumpPEFromMemory/DumpPEFromMemory.vcxproj b/DumpPEFromMemory/DumpPEFromMemory.vcxproj new file mode 100644 index 0000000..63362e0 --- /dev/null +++ b/DumpPEFromMemory/DumpPEFromMemory.vcxproj @@ -0,0 +1,135 @@ + + + + + Debug + Win32 + + + Release + Win32 + + + Debug + x64 + + + Release + x64 + + + + 17.0 + Win32Proj + {eec48565-5b42-491a-8bbb-16ac0c40c367} + DumpPEFromMemory + 10.0 + + + + Application + true + v143 + Unicode + + + Application + false + v143 + true + Unicode + + + Application + true + v143 + Unicode + + + Application + false + v143 + true + Unicode + + + + + + + + + + + + + + + + + + + + + + Level3 + true + WIN32;_DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + WIN32;NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + Level3 + true + _DEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + + + + + Level3 + true + true + true + NDEBUG;_CONSOLE;%(PreprocessorDefinitions) + true + + + Console + true + true + true + + + + + + + + + \ No newline at end of file diff --git a/DumpPEFromMemory/DumpPEFromMemory.vcxproj.filters b/DumpPEFromMemory/DumpPEFromMemory.vcxproj.filters new file mode 100644 index 0000000..ff563d4 --- /dev/null +++ b/DumpPEFromMemory/DumpPEFromMemory.vcxproj.filters @@ -0,0 +1,22 @@ + + + + + {4FC737F1-C7A5-4376-A066-2A32D752A2FF} + cpp;c;cc;cxx;c++;cppm;ixx;def;odl;idl;hpj;bat;asm;asmx + + + {93995380-89BD-4b04-88EB-625FBE52EBFB} + h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd + + + {67DA6AB6-F800-4c08-8B7A-83BB121AAD01} + rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms + + + + + Source Files + + + \ No newline at end of file diff --git a/DumpPEFromMemory/DumpPEFromMemory.vcxproj.user b/DumpPEFromMemory/DumpPEFromMemory.vcxproj.user new file mode 100644 index 0000000..0f14913 --- /dev/null +++ b/DumpPEFromMemory/DumpPEFromMemory.vcxproj.user @@ -0,0 +1,4 @@ + + + + \ No newline at end of file