
다양한 EDR 우회 기법을 기반으로 한 C++ 자가 주입형 드로퍼.
이 프로젝트는 EDR 우회 POC에 초점을 맞춘 간단한 C++ 자체 주입 드로퍼로 구성되어 있습니다. 구현을 위해 콜 스택을 숨기기 위한 Windows Thread Pooling 과 NTDLL 후킹을 피하기 위한 indirect syscalls 사용을 결합했습니다.
2023-10-08-23-22-35-Trim
image
image
image
image
이미지에서 볼 수 있듯이, Cordyceps 코드는 syscall 명령어 중 하나를 활용하기 위해 ntdll로 점프를 수행합니다. 이는 악성 행위로 간주되어야 합니다. 그러나 ntdll에서 반환을 실행하면 ntdll 내부에 위치한 tpWorker의 코드로 돌아갑니다. 따라서 안티바이러스(AV)의 관점에서 보면 ntdll이 ntdll의 다른 부분을 호출하는 것처럼 보이므로 악성으로 간주되지 않습니다.
nasm -f win64 .\Assembly.asm -o .\Assembly.obj
g++ -o poc.exe main.cpp Assembly.obj
https://0xdarkvortex.dev/hiding-in-plainsight/
https://redops.at/en/blog/direct-syscalls-vs-indirect-syscalls
https://captmeelo.com/redteam/maldev/2022/05/10/ntcreateuserprocess.html
https://klezvirus.github.io/RedTeaming/AV_Evasion/StackSpoofing/
https://medium.com/@sruthk/cracking-assembly-fastcall-calling-convention-in-x64-c6d77b51ea86