Adjusting function names to maintain obfuscation

This commit is contained in:
toneillcodes
2026-04-07 11:03:12 -04:00
parent 1ab7be871d
commit d717869c63
4 changed files with 8 additions and 8 deletions
+3 -3
View File
@@ -48,8 +48,8 @@ PVOID GetRemotePebAddress(HANDLE hProcess) {
}
// find the address of an exported function within a given module
// obviously depends on a name value being present in the array found at AddressOfNames
PVOID GetProcAddressManualByName(HMODULE hMod, char* targetFunc) {
// depends on a name value being present in the array found at AddressOfNames
PVOID GPAManualByName(HMODULE hMod, char* targetFunc) {
PBYTE base = (PBYTE)hMod;
PIMAGE_DOS_HEADER dos = (PIMAGE_DOS_HEADER)base;
@@ -102,7 +102,7 @@ PVOID GetProcAddressManualByName(HMODULE hMod, char* targetFunc) {
}
// find the address of an exported function within a given module
PVOID GetProcAddressManualByOrdinal(HMODULE hMod, WORD ordinal) {
PVOID GPAManualByOrdinal(HMODULE hMod, WORD ordinal) {
PBYTE base = (PBYTE)hMod;
// 1. Navigate to the Export Directory (standard PE parsing)
+2 -2
View File
@@ -22,10 +22,10 @@ PVOID GetRemotePebAddress(HANDLE hProcess);
int my_strlen(const char* inputString);
// Manual implementation of GetProcAddress (by name)
PVOID GetProcAddressManualByName(HMODULE hMod, char* targetFunc);
PVOID GPAManualByName(HMODULE hMod, char* targetFunc);
// Manual implementation of GetProcAddress (by ordinal)
PVOID GetProcAddressManualByOrdinal(HMODULE hMod, WORD ordinal);
PVOID GPAManualByOrdinal(HMODULE hMod, WORD ordinal);
// Manually finds the base address of a module using the PEB's Ldr list
PVOID GetModuleBaseManual(PPEB pebObject, const char* targetModuleName);
+2 -2
View File
@@ -86,7 +86,7 @@ int main(int argc, char* argv[]) {
}
//ParseDll(moduleBaseAddress);
PVOID moduleBase = moduleBaseAddress;
// 1. Get DOS Header
// Get DOS Header
PIMAGE_DOS_HEADER dosHeader = (PIMAGE_DOS_HEADER)moduleBase;
if (dosHeader->e_magic != IMAGE_DOS_SIGNATURE) {
printf("Invalid DOS Signature\n");
@@ -159,7 +159,7 @@ int main(int argc, char* argv[]) {
// Iterate through every function exported by the DLL
for (DWORD i = 0; i < NumberOfFunctions; i++) {
// 1. Get the Function RVA directly using the index 'i'
// Get the Function RVA directly using the index 'i'
DWORD functionRVA = functionsArray[i];
if (functionRVA == 0) continue; // Skip entries with no address
+1 -1
View File
@@ -55,7 +55,7 @@ int main(int argc, char* argv[]) {
PVOID dllBase = GetModuleBaseManual(peb_ptr, "USER32.dll"); // or maybe ntdll.dll
if(dllBase) {
printf("DLL found @ %llx\n",dllBase);
PVOID rvaFound = GetProcAddressManualByName((HMODULE) dllBase, "MessageBoxA"); // and then NtAllocateVirtualMemory
PVOID rvaFound = GPAManualByName((HMODULE) dllBase, "MessageBoxA"); // and then NtAllocateVirtualMemory
if(rvaFound) {
printf("found function within DLL @ %llx\n", rvaFound);
// MessageBoxA example