Skip to content

Not working on windows 11 24H2 #3

@idigger

Description

@idigger
C:\test>"Process Hollowing x64.exe" c:\windows\system32\svchost.exe payload64.exe
Creating Susspended Process. [c:\windows\system32\svchost.exe]
Mamming File To Memory. [payload64.exe]
Geting Current Context.
Unmapping Section.
Original Process Base: 0x140000000
Evil File Base: 0x7ff64cdc0000
Offset: 0x7ff50cdc0000

Writing Sections:
0x4cdc1000 -- Writing Section: .text
0x4cdd1000 -- Writing Section: .rdata
0x4cdd9000 -- Writing Section: .data
0x4cddd000 -- Writing Section: .pdata
0x4cdde000 -- Writing Section: .rsrc
0x4cddf000 -- Writing Section: .reloc

Relocating The Relocation Table...

Relocation Block 0x11000. Size: 0x54
38 Entries Must Be Realocated In The Current Block.
0x140001018 --> 0x7ff64cdc1018 | At:0x7ff64cdd1260
0x140001000 --> 0x7ff64cdc1000 | At:0x7ff64cdd1268
0x14000205c --> 0x7ff64cdc205c | At:0x7ff64cdd1280
0x140006bd4 --> 0x7ff64cdc6bd4 | At:0x7ff64cdd1288
0x14000760c --> 0x7ff64cdc760c | At:0x7ff64cdd1290
0x140007ff8 --> 0x7ff64cdc7ff8 | At:0x7ff64cdd1298
0x1400052bc --> 0x7ff64cdc52bc | At:0x7ff64cdd12a0
......
0x140016864 --> 0x7ff64cdd6864 | At:0x7ff64cdda298
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda5c0
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda5e0
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda608
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda630
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda658
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda680
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda6a8
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda6d0
The Type Of Base Relocation Is 0. Skipping.

Setting Thread Context.
Resuming Thread.

Done. Enjoy The "New" Process.
---------------------------------

errrrrrr

It's ok on before windows 11 24H2

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions