XTrap Process Termination (Handle Swap)

Posts 1–6 of 6 · Page 1 of 1
XTrap Process Termination (Handle Swap)
Code:
// XTrapVa.dll hook at: FF 50 64 8B F8 (alternate sig: 75 20 8B 96 ? ? ? ? 8D 8E ? ? ? ? FF 12 8B C8 8B 44 24 18 5F 5E 89 18 5D 89 48 04 5B C2 10 00 - 0x7)
Code:
XTrapVa.dll+3990A1 - 55                    - push ebp
XTrapVa.dll+3990A2 - 56                    - push esi
XTrapVa.dll+3990A3 - 8B 74 24 10           - mov esi,[esp+10]
XTrapVa.dll+3990A7 - 57                    - push edi
XTrapVa.dll+3990A8 - 33 DB                 - xor ebx,ebx
XTrapVa.dll+3990AA - 8B 46 04              - mov eax,[esi+04]
XTrapVa.dll+3990AD - 8D 4E 04              - lea ecx,[esi+04]
XTrapVa.dll+3990B0 - 33 ED                 - xor ebp,ebp
XTrapVa.dll+3990B2 - FF 50 64              - call dword ptr [eax+64]
XTrapVa.dll+3990B5 - 8B F8                 - mov edi,eax
XTrapVa.dll+3990B7 - 85 FF                 - test edi,edi
XTrapVa.dll+3990B9 - 75 20                 - jne XTrapVa.dll+3990DB
XTrapVa.dll+3990BB - 8B 96 50110000        - mov edx,[esi+00001150]
XTrapVa.dll+3990C1 - 8D 8E 50110000        - lea ecx,[esi+00001150]
XTrapVa.dll+3990C7 - FF 12                 - call dword ptr [edx]
XTrapVa.dll+3990C9 - 8B C8                 - mov ecx,eax
XTrapVa.dll+3990CB - 8B 44 24 18           - mov eax,[esp+18]
XTrapVa.dll+3990CF - 5F                    - pop edi
XTrapVa.dll+3990D0 - 5E                    - pop esi
XTrapVa.dll+3990D1 - 89 18                 - mov [eax],ebx
XTrapVa.dll+3990D3 - 5D                    - pop ebp
XTrapVa.dll+3990D4 - 89 48 04              - mov [eax+04],ecx
XTrapVa.dll+3990D7 - 5B                    - pop ebx
XTrapVa.dll+3990D8 - C2 1000               - ret 0010 { 16 }
XTrapVa.dll+3990DB - 8B 86 F45A0000        - mov eax,[esi+00005AF4]
XTrapVa.dll+3990E1 - 8D 8E F45A0000        - lea ecx,[esi+00005AF4]
XTrapVa.dll+3990E7 - FF 10                 - call dword ptr [eax]
XTrapVa.dll+3990E9 - 8B 4C 24 20           - mov ecx,[esp+20]
XTrapVa.dll+3990ED - 8B 54 24 1C           - mov edx,[esp+1C]
XTrapVa.dll+3990F1 - 51                    - push ecx
XTrapVa.dll+3990F2 - 52                    - push edx
XTrapVa.dll+3990F3 - FF D7                 - call edi
XTrapVa.dll+3990F5 - 8D 8E D85A0000        - lea ecx,[esi+00005AD8]
XTrapVa.dll+3990FB - 8B F8                 - mov edi,eax
XTrapVa.dll+3990FD - 8B 01                 - mov eax,[ecx]
XTrapVa.dll+3990FF - FF 10                 - call dword ptr [eax]
XTrapVa.dll+399101 - 3B F8                 - cmp edi,eax
XTrapVa.dll+399103 - 75 20                 - jne XTrapVa.dll+399125
XTrapVa.dll+399105 - 8B 96 5C4F0000        - mov edx,[esi+00004F5C]
XTrapVa.dll+39910B - 8D 8E 5C4F0000        - lea ecx,[esi+00004F5C]
XTrapVa.dll+399111 - FF 12                 - call dword ptr [edx]
XTrapVa.dll+399113 - 8B 4C 24 18           - mov ecx,[esp+18]
XTrapVa.dll+399117 - 5F                    - pop edi
XTrapVa.dll+399118 - 5E                    - pop esi
XTrapVa.dll+399119 - 89 01                 - mov [ecx],eax
XTrapVa.dll+39911B - 89 69 04              - mov [ecx+04],ebp
XTrapVa.dll+39911E - 5D                    - pop ebp
XTrapVa.dll+39911F - 8B C1                 - mov eax,ecx
XTrapVa.dll+399121 - 5B                    - pop ebx
XTrapVa.dll+399122 - C2 1000               - ret 0010 { 16 }
XTrapVa.dll+399125 - 8B 86 784F0000        - mov eax,[esi+00004F78]
XTrapVa.dll+39912B - 8D 8E 784F0000        - lea ecx,[esi+00004F78]
XTrapVa.dll+399131 - FF 10                 - call dword ptr [eax]
XTrapVa.dll+399133 - 8B 4C 24 18           - mov ecx,[esp+18]
XTrapVa.dll+399137 - 8B EF                 - mov ebp,edi
XTrapVa.dll+399139 - 5F                    - pop edi
XTrapVa.dll+39913A - 5E                    - pop esi
XTrapVa.dll+39913B - 89 01                 - mov [ecx],eax
XTrapVa.dll+39913D - 89 69 04              - mov [ecx+04],ebp
XTrapVa.dll+399140 - 5D                    - pop ebp
XTrapVa.dll+399141 - 8B C1                 - mov eax,ecx
XTrapVa.dll+399143 - 5B                    - pop ebx
XTrapVa.dll+399144 - C2 1000               - ret 0010 { 16 }
Code:
DWORD g_dwProcId = 0;
HANDLE g_hDecoyProc = nullptr;
STARTUPINFOA g_sInfo = {};
PROCESS_INFORMATION g_pInfo = {};
 
__declspec(naked)void hkProcessTermination(void)
{
    // Save stack & flags
    __asm pushad;
    __asm pushfd;
 
    // [esp + 0x1C] == Handle of detected tool
 
    // Start decoy process
    CreateProcessA("C:\\mydecoy.exe", nullptr, nullptr, nullptr, FALSE, NULL, nullptr, nullptr, &g_sInfo, &g_pInfo);
 
    // Wait for process to launch
    while (true)
    {
        // Get decoy process ID (also indication that the process is running once value is non-zero)
        g_dwProcId = GetProcessID("mydecoy.exe");
 
        // Check if the process ID is non-zero, if so break out the loop
        if (g_dwProcId != NULL)
            break;
    }
 
    // Open handle to our decoy process (we need this handle to bypass the check)
    g_hDecoyProc = OpenProcess(PROCESS_ALL_ACCESS, FALSE, g_dwProcId);
 
    // Restore stack & flags
    __asm popfd;
    __asm popad;
 
    // Copy our decoy process handle to the data register which then modifies 0x1C within the stack pointer
    __asm mov edx, g_hDecoyProc;
    __asm mov[esp + 0x1C], edx;
    // There is no need to restore EDX as it gets overwritten
 
    // Original Code
    __asm call dword ptr[eax + 0x64];
    __asm mov edi, eax;
 
    // Continue Execution
    __asm jmp[g_dwContinue];
}
Credit : M4L1



Code:
https://www.virustotal.com/#/file/e12ccc7ba8dfc1f8f7f9c8a6be8646c18ecdb911618118a1c9f0dcacd2d68e79/detection
XTrapVa_dump_mpgh.net.zip7.5 MB · 91 downloads 3/58 malicious
Thanks for share i will try this on CF XTRAP Philippines
i think this xtrap is for CFPH right i check it same offset
Quote Originally Posted by iknowitsfake26 View Post
i think this xtrap is for CFPH right i check it same offset
What is the result have you tried already? If works try to open CE.
Ohh he just re-posted this from other forum, nothing change..
this has been posted already.
Posts 1–6 of 6 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us