
विभिन्न EDR एवेज़न तकनीकों पर आधारित C++ स्व-इंजेक्टिंग ड्रॉपर।
यह प्रोजेक्ट एक साधारण C++ सेल्फ-इंजेक्टिंग ड्रॉपर है जो EDR एवेज़न POC पर केंद्रित है। इसे लागू करने के लिए, मैंने Windows Thread Pooling का उपयोग कॉल स्टैक को छिपाने के लिए और indirect syscalls का उपयोग NTDLL में हुकिंग से बचने के लिए संयुक्त रूप से किया है।
2023-10-08-23-22-35-Trim
image
image
image
image
जैसा कि छवियों में देखा जा सकता है, Cordyceps कोड से, यह syscall निर्देशों में से एक का उपयोग करने के लिए ntdll पर एक जंप करता है। इसे एक दुर्भावनापूर्ण क्रिया माना जाना चाहिए; हालाँकि, ntdll में रिटर्न निष्पादित करने पर, हम tpWorker के कोड पर लौटते हैं, जो ntdll के भीतर स्थित है। इस प्रकार, एंटीवायरस (AV) के दृष्टिकोण से, ntdll ऐसा प्रतीत होगा जैसे वह ntdll के किसी अन्य भाग को कॉल कर रहा है, जिसे दुर्भावनापूर्ण नहीं माना जाता है।
nasm -f win64 .\Assembly.asm -o .\Assembly.obj
g++ -o poc.exe main.cpp Assembly.obj
https://0xdarkvortex.dev/hiding-in-plainsight/
https://redops.at/en/blog/direct-syscalls-vs-indirect-syscalls
https://captmeelo.com/redteam/maldev/2022/05/10/ntcreateuserprocess.html
https://klezvirus.github.io/RedTeaming/AV_Evasion/StackSpoofing/
https://medium.com/@sruthk/cracking-assembly-fastcall-calling-convention-in-x64-c6d77b51ea86