Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  Hollowed Process

Topic created on: January 8, 2013 02:10 CST by legola .

Hi, i'm analyzing a malware that call CreateProcess (CREATE_SUSPENDED) function to create a new iexplore.exe process, use VirtualAllocEx, WriteProcess Memory and CreateRemoteThread to inject its code in it. I'm trying to attach the suspended process to windbg before CreateRemoteThread is call but i have problems. WinDBG say me that the process is invalid, or something like this.Is there someone can help me ? Thank you

  waleedassar     January 14, 2013 03:54.24 CST
This might help.
http://hooked-on-mnemonics.blogspot.com/2013/01/debugging-hollow-processes.html

  legola     January 15, 2013 15:31.04 CST
Hi waleedassar, thank you for reply.
I already read that article.
Have you idea why windbg is giving me that problems?

  anonymouse     January 16, 2013 03:12.15 CST
try using the .childdbg functionality in this plugin and see if it works

https://www.openrce.org/repositories/users/anonymouse/ModifiedCommandLinePluginWithChildDbg_Date_16082008.rar

  legola     January 29, 2013 12:43.36 CST
Hi, i have problems to download that file.

  codeinject     January 30, 2013 02:18.04 CST
> legola: Hi, i have problems to download that file.

Eleborate!

  legola     January 30, 2013 10:22.25 CST
Hi, i have problems because i see ascii text in browser during request.
Maybe some invalid char in archive ? Thanks

  codeinject     January 31, 2013 04:56.38 CST
Try wget-ting it.

  anonymouse     February 1, 2013 14:50.17 CST
if on firefox do right click save link as
or copy the link and wget -c

Note: Registration is required to post to the forums.

There are 31,056 total registered users.


Recently Created Topics
Ultimate Hacking Cha...
Jun/21
CreateMutex
May/31
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06
Immunity Debugger Re...
Aug/03


Recent Forum Posts
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n
OOP_RE tool available?
van7hu
Should binaries be n...
Kolisar
Problem with ollydbg
nullx42
!findtrampoline Immu...
skycrack


Recent Blog Entries
crystalwade
Jul/20
test

nieo
Mar/22
Android Application Reversing

halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit