-
Notifications
You must be signed in to change notification settings - Fork 178
/
Copy pathcobf_8hpp_source.html
234 lines (232 loc) · 22 KB
/
cobf_8hpp_source.html
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "https://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/xhtml;charset=UTF-8"/>
<meta http-equiv="X-UA-Compatible" content="IE=9"/>
<meta name="generator" content="Doxygen 1.8.20"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<title>cobf: include/cobf.hpp Source File</title>
<link href="tabs.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="jquery.js"></script>
<script type="text/javascript" src="dynsections.js"></script>
<link href="navtree.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="resize.js"></script>
<script type="text/javascript" src="navtreedata.js"></script>
<script type="text/javascript" src="navtree.js"></script>
<link href="search/search.css" rel="stylesheet" type="text/css"/>
<script type="text/javascript" src="search/searchdata.js"></script>
<script type="text/javascript" src="search/search.js"></script>
<link href="doxygen.css" rel="stylesheet" type="text/css" />
</head>
<body>
<div id="top"><!-- do not remove this div, it is closed by doxygen! -->
<div id="titlearea">
<table cellspacing="0" cellpadding="0">
<tbody>
<tr style="height: 56px;">
<td id="projectalign" style="padding-left: 0.5em;">
<div id="projectname">cobf
</div>
<div id="projectbrief">PE imports obfuscator</div>
</td>
</tr>
</tbody>
</table>
</div>
<!-- end header part -->
<!-- Generated by Doxygen 1.8.20 -->
<script type="text/javascript">
/* @license magnet:?xt=urn:btih:cf05388f2679ee054f2beb29a391d25f4e673ac3&dn=gpl-2.0.txt GPL-v2 */
var searchBox = new SearchBox("searchBox", "search",false,'Search');
/* @license-end */
</script>
<script type="text/javascript" src="menudata.js"></script>
<script type="text/javascript" src="menu.js"></script>
<script type="text/javascript">
/* @license magnet:?xt=urn:btih:cf05388f2679ee054f2beb29a391d25f4e673ac3&dn=gpl-2.0.txt GPL-v2 */
$(function() {
initMenu('',true,false,'search.php','Search');
$(document).ready(function() { init_search(); });
});
/* @license-end */</script>
<div id="main-nav"></div>
</div><!-- top -->
<div id="side-nav" class="ui-resizable side-nav-resizable">
<div id="nav-tree">
<div id="nav-tree-contents">
<div id="nav-sync" class="sync"></div>
</div>
</div>
<div id="splitbar" style="-moz-user-select:none;"
class="ui-resizable-handle">
</div>
</div>
<script type="text/javascript">
/* @license magnet:?xt=urn:btih:cf05388f2679ee054f2beb29a391d25f4e673ac3&dn=gpl-2.0.txt GPL-v2 */
$(document).ready(function(){initNavTree('cobf_8hpp_source.html',''); initResizable(); });
/* @license-end */
</script>
<div id="doc-content">
<!-- window showing the filter options -->
<div id="MSearchSelectWindow"
onmouseover="return searchBox.OnSearchSelectShow()"
onmouseout="return searchBox.OnSearchSelectHide()"
onkeydown="return searchBox.OnSearchSelectKey(event)">
</div>
<!-- iframe showing the search results (closed by default) -->
<div id="MSearchResultsWindow">
<iframe src="javascript:void(0)" frameborder="0"
name="MSearchResults" id="MSearchResults">
</iframe>
</div>
<div class="header">
<div class="headertitle">
<div class="title">cobf.hpp</div> </div>
</div><!--header-->
<div class="contents">
<a href="cobf_8hpp.html">Go to the documentation of this file.</a><div class="fragment"><div class="line"><a name="l00001"></a><span class="lineno"> 1</span>  </div>
<div class="line"><a name="l00009"></a><span class="lineno"> 9</span> <span class="preprocessor">#ifndef COBF_HPP</span></div>
<div class="line"><a name="l00010"></a><span class="lineno"> 10</span> <span class="preprocessor">#define COBF_HPP</span></div>
<div class="line"><a name="l00011"></a><span class="lineno"> 11</span>  </div>
<div class="line"><a name="l00012"></a><span class="lineno"> 12</span> <span class="comment">// Includes.</span></div>
<div class="line"><a name="l00013"></a><span class="lineno"> 13</span> <span class="preprocessor">#include <<a class="code" href="shellcode_8hpp.html">shellcode.hpp</a>></span></div>
<div class="line"><a name="l00014"></a><span class="lineno"> 14</span> <span class="preprocessor">#include <<a class="code" href="utils_8hpp.html">utils.hpp</a>></span></div>
<div class="line"><a name="l00015"></a><span class="lineno"> 15</span> <span class="preprocessor">#include <algorithm></span></div>
<div class="line"><a name="l00016"></a><span class="lineno"> 16</span> <span class="preprocessor">#include <string></span></div>
<div class="line"><a name="l00017"></a><span class="lineno"> 17</span> <span class="preprocessor">#include <vector></span></div>
<div class="line"><a name="l00018"></a><span class="lineno"> 18</span> <span class="preprocessor">#include <map></span></div>
<div class="line"><a name="l00019"></a><span class="lineno"> 19</span> <span class="keyword">using namespace </span>std;</div>
<div class="line"><a name="l00020"></a><span class="lineno"> 20</span>  </div>
<div class="line"><a name="l00025"></a><span class="lineno"><a class="line" href="classcobf.html"> 25</a></span> <span class="keyword">class </span><a class="code" href="classcobf.html">cobf</a></div>
<div class="line"><a name="l00026"></a><span class="lineno"> 26</span> {</div>
<div class="line"><a name="l00027"></a><span class="lineno"> 27</span> <span class="keyword">private</span>:</div>
<div class="line"><a name="l00028"></a><span class="lineno"> 28</span>  </div>
<div class="line"><a name="l00029"></a><span class="lineno"> 29</span>  <span class="comment">// Each symbol.</span></div>
<div class="line"><a name="l00030"></a><span class="lineno"> 30</span>  <span class="keyword">class </span>csym {</div>
<div class="line"><a name="l00031"></a><span class="lineno"> 31</span>  <span class="keyword">private</span>:</div>
<div class="line"><a name="l00032"></a><span class="lineno"> 32</span>  </div>
<div class="line"><a name="l00033"></a><span class="lineno"> 33</span>  <span class="keywordtype">string</span> sym_name; </div>
<div class="line"><a name="l00034"></a><span class="lineno"> 34</span>  DWORD dll_rva; </div>
<div class="line"><a name="l00035"></a><span class="lineno"> 35</span>  WORD sym_ord; </div>
<div class="line"><a name="l00036"></a><span class="lineno"> 36</span>  DWORD fth_rva; </div>
<div class="line"><a name="l00037"></a><span class="lineno"> 37</span>  DWORD oth_off; </div>
<div class="line"><a name="l00038"></a><span class="lineno"> 38</span>  DWORD name_off; </div>
<div class="line"><a name="l00039"></a><span class="lineno"> 39</span>  BOOL by_name; </div>
<div class="line"><a name="l00040"></a><span class="lineno"> 40</span>  BOOL obfuscated; </div>
<div class="line"><a name="l00041"></a><span class="lineno"> 41</span>  <span class="keywordtype">string</span> obf_name; </div>
<div class="line"><a name="l00042"></a><span class="lineno"> 42</span>  WORD obf_ord; </div>
<div class="line"><a name="l00043"></a><span class="lineno"> 43</span>  BOOL to_name; </div>
<div class="line"><a name="l00045"></a><span class="lineno"> 45</span>  <span class="keyword">public</span>:</div>
<div class="line"><a name="l00046"></a><span class="lineno"> 46</span>  </div>
<div class="line"><a name="l00053"></a><span class="lineno"> 53</span>  <span class="keyword">static</span> BOOL match_wildcard(PCCH wild_card, PCCH <span class="keywordtype">string</span>);</div>
<div class="line"><a name="l00054"></a><span class="lineno"> 54</span>  </div>
<div class="line"><a name="l00063"></a><span class="lineno"> 63</span>  csym(<span class="keywordtype">string</span> sym_name, DWORD dll_rva, DWORD fth_rva, DWORD oth_off, DWORD name_off);</div>
<div class="line"><a name="l00064"></a><span class="lineno"> 64</span>  </div>
<div class="line"><a name="l00072"></a><span class="lineno"> 72</span>  csym(WORD sym_ord, DWORD dll_rva, DWORD fth_rva, DWORD oth_off);</div>
<div class="line"><a name="l00073"></a><span class="lineno"> 73</span>  </div>
<div class="line"><a name="l00079"></a><span class="lineno"> 79</span>  BOOL check_sym(<span class="keywordtype">string</span> n_sym);</div>
<div class="line"><a name="l00080"></a><span class="lineno"> 80</span>  </div>
<div class="line"><a name="l00086"></a><span class="lineno"> 86</span>  BOOL check_sym(WORD n_ord);</div>
<div class="line"><a name="l00087"></a><span class="lineno"> 87</span>  </div>
<div class="line"><a name="l00092"></a><span class="lineno"> 92</span>  VOID obfuscate(<span class="keywordtype">string</span> o_sym);</div>
<div class="line"><a name="l00093"></a><span class="lineno"> 93</span>  </div>
<div class="line"><a name="l00098"></a><span class="lineno"> 98</span>  VOID obfuscate(WORD o_ord);</div>
<div class="line"><a name="l00099"></a><span class="lineno"> 99</span>  </div>
<div class="line"><a name="l00103"></a><span class="lineno"> 103</span>  VOID unobfuscate();</div>
<div class="line"><a name="l00104"></a><span class="lineno"> 104</span>  </div>
<div class="line"><a name="l00112"></a><span class="lineno"> 112</span>  VOID apply_obfuscation(PBYTE pe_rawf, DWORD strings_off, vector<BYTE>& strings,</div>
<div class="line"><a name="l00113"></a><span class="lineno"> 113</span>  vector<shellcode::obfuscated_sym>& symbols);</div>
<div class="line"><a name="l00114"></a><span class="lineno"> 114</span>  };</div>
<div class="line"><a name="l00115"></a><span class="lineno"> 115</span>  </div>
<div class="line"><a name="l00116"></a><span class="lineno"> 116</span>  <span class="comment">// Each module.</span></div>
<div class="line"><a name="l00117"></a><span class="lineno"> 117</span>  <span class="keyword">struct </span>cmod {</div>
<div class="line"><a name="l00118"></a><span class="lineno"> 118</span>  <span class="keywordtype">string</span> dll_name; </div>
<div class="line"><a name="l00119"></a><span class="lineno"> 119</span>  vector<csym> mod_syms; </div>
<div class="line"><a name="l00120"></a><span class="lineno"> 120</span>  };</div>
<div class="line"><a name="l00121"></a><span class="lineno"> 121</span>  </div>
<div class="line"><a name="l00122"></a><span class="lineno"> 122</span>  <span class="keywordtype">string</span> pe_path; </div>
<div class="line"><a name="l00123"></a><span class="lineno"> 123</span>  vector<BYTE> pe_rawf; </div>
<div class="line"><a name="l00124"></a><span class="lineno"> 124</span>  vector<cmod> pe_mods; </div>
<div class="line"><a name="l00130"></a><span class="lineno"> 130</span>  BOOL disable_the_relocation();</div>
<div class="line"><a name="l00131"></a><span class="lineno"> 131</span>  </div>
<div class="line"><a name="l00136"></a><span class="lineno"> 136</span>  BOOL remove_debug_symbols();</div>
<div class="line"><a name="l00137"></a><span class="lineno"> 137</span>  </div>
<div class="line"><a name="l00142"></a><span class="lineno"> 142</span>  BOOL make_the_iat_writable();</div>
<div class="line"><a name="l00143"></a><span class="lineno"> 143</span>  </div>
<div class="line"><a name="l00151"></a><span class="lineno"> 151</span>  <span class="keyword">template</span> <<span class="keyword">typename</span> t_sym_info></div>
<div class="line"><a name="l00152"></a><span class="lineno"> 152</span>  VOID find_symbols(<span class="keywordtype">string</span> dll_name, t_sym_info sym_info, vector<csym*>& p_syms);</div>
<div class="line"><a name="l00153"></a><span class="lineno"> 153</span>  </div>
<div class="line"><a name="l00160"></a><span class="lineno"> 160</span>  BOOL add_shellcode_entry(PIMAGE_SECTION_HEADER& sh_sec, DWORD entry);</div>
<div class="line"><a name="l00161"></a><span class="lineno"> 161</span>  </div>
<div class="line"><a name="l00168"></a><span class="lineno"> 168</span>  BOOL section_of_rva(DWORD rva, PIMAGE_SECTION_HEADER& sec);</div>
<div class="line"><a name="l00169"></a><span class="lineno"> 169</span>  </div>
<div class="line"><a name="l00176"></a><span class="lineno"> 176</span>  BOOL rva_to_offset(DWORD rva, DWORD& offset);</div>
<div class="line"><a name="l00177"></a><span class="lineno"> 177</span>  </div>
<div class="line"><a name="l00184"></a><span class="lineno"> 184</span>  BOOL rva_to_ptr(DWORD ptr_rva, PVOID* p_ptr);</div>
<div class="line"><a name="l00185"></a><span class="lineno"> 185</span>  </div>
<div class="line"><a name="l00192"></a><span class="lineno"> 192</span>  BOOL create_shellcode_section(PIMAGE_SECTION_HEADER& sh_sec, DWORD& funs_rva);</div>
<div class="line"><a name="l00193"></a><span class="lineno"> 193</span>  </div>
<div class="line"><a name="l00201"></a><span class="lineno"> 201</span>  BOOL get_data_table(<span class="keywordtype">size_t</span> data_entry, PVOID* p_table_ptr, <span class="keywordtype">size_t</span>& table_size);</div>
<div class="line"><a name="l00202"></a><span class="lineno"> 202</span>  </div>
<div class="line"><a name="l00208"></a><span class="lineno"> 208</span>  BOOL get_dos_header(PIMAGE_DOS_HEADER& dos_hdr);</div>
<div class="line"><a name="l00209"></a><span class="lineno"> 209</span>  </div>
<div class="line"><a name="l00216"></a><span class="lineno"> 216</span>  BOOL get_nt_headers(PIMAGE_DOS_HEADER dos_hdr, PIMAGE_NT_HEADERS& nt_hdrs);</div>
<div class="line"><a name="l00217"></a><span class="lineno"> 217</span>  </div>
<div class="line"><a name="l00223"></a><span class="lineno"> 223</span>  BOOL verify_machine(PIMAGE_NT_HEADERS nt_hdrs);</div>
<div class="line"><a name="l00224"></a><span class="lineno"> 224</span>  </div>
<div class="line"><a name="l00231"></a><span class="lineno"> 231</span>  BOOL verify_sections(PIMAGE_DOS_HEADER dos_hdr, PIMAGE_NT_HEADERS nt_hdrs);</div>
<div class="line"><a name="l00232"></a><span class="lineno"> 232</span>  </div>
<div class="line"><a name="l00242"></a><span class="lineno"> 242</span>  BOOL insert_import(cmod& dll_mod, DWORD dll_off, <span class="keywordtype">size_t</span> th_sym, DWORD fth_rva, DWORD oth_off);</div>
<div class="line"><a name="l00243"></a><span class="lineno"> 243</span>  </div>
<div class="line"><a name="l00250"></a><span class="lineno"> 250</span>  BOOL parse_imports(PIMAGE_IMPORT_DESCRIPTOR p_imports, <span class="keywordtype">size_t</span> imports_size);</div>
<div class="line"><a name="l00251"></a><span class="lineno"> 251</span>  </div>
<div class="line"><a name="l00257"></a><span class="lineno"> 257</span>  VOID apply_obfuscations(PIMAGE_SECTION_HEADER& sh_sec, DWORD& syms_rva);</div>
<div class="line"><a name="l00258"></a><span class="lineno"> 258</span>  </div>
<div class="line"><a name="l00266"></a><span class="lineno"> 266</span>  VOID add_shellcode_stub(PIMAGE_SECTION_HEADER& sh_sec, DWORD funs_offset, DWORD syms_rva, DWORD& entry);</div>
<div class="line"><a name="l00267"></a><span class="lineno"> 267</span>  </div>
<div class="line"><a name="l00272"></a><span class="lineno"> 272</span>  VOID finalize_pe(PIMAGE_SECTION_HEADER& sh_sec);</div>
<div class="line"><a name="l00273"></a><span class="lineno"> 273</span>  </div>
<div class="line"><a name="l00283"></a><span class="lineno"> 283</span>  <span class="keyword">template</span> <<span class="keyword">typename</span> t_sym_info, <span class="keyword">typename</span> t_obf_info></div>
<div class="line"><a name="l00284"></a><span class="lineno"> 284</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> obf_sym_internal(<span class="keywordtype">string</span> dll_name, t_sym_info sym_info, t_obf_info obf_info);</div>
<div class="line"><a name="l00285"></a><span class="lineno"> 285</span>  </div>
<div class="line"><a name="l00294"></a><span class="lineno"> 294</span>  <span class="keyword">template</span> <<span class="keyword">typename</span> t_sym_info></div>
<div class="line"><a name="l00295"></a><span class="lineno"> 295</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> unobf_sym_internal(<span class="keywordtype">string</span> dll_name, t_sym_info sym_info);</div>
<div class="line"><a name="l00296"></a><span class="lineno"> 296</span>  </div>
<div class="line"><a name="l00297"></a><span class="lineno"> 297</span> <span class="keyword">public</span>:</div>
<div class="line"><a name="l00303"></a><span class="lineno"> 303</span>  <a class="code" href="classcobf.html">cobf</a>(<span class="keywordtype">string</span> pe_path);</div>
<div class="line"><a name="l00304"></a><span class="lineno"> 304</span>  </div>
<div class="line"><a name="l00321"></a><span class="lineno"> 321</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> load_pe();</div>
<div class="line"><a name="l00322"></a><span class="lineno"> 322</span>  </div>
<div class="line"><a name="l00329"></a><span class="lineno"> 329</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> unload_pe();</div>
<div class="line"><a name="l00330"></a><span class="lineno"> 330</span>  </div>
<div class="line"><a name="l00340"></a><span class="lineno"> 340</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> obf_sym(<span class="keywordtype">string</span> dll_name, <span class="keywordtype">string</span> sym_name, <span class="keywordtype">string</span> obf_name);</div>
<div class="line"><a name="l00341"></a><span class="lineno"> 341</span>  </div>
<div class="line"><a name="l00351"></a><span class="lineno"> 351</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> obf_sym(<span class="keywordtype">string</span> dll_name, <span class="keywordtype">string</span> sym_name, WORD obf_ord);</div>
<div class="line"><a name="l00352"></a><span class="lineno"> 352</span>  </div>
<div class="line"><a name="l00362"></a><span class="lineno"> 362</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> obf_sym(<span class="keywordtype">string</span> dll_name, WORD sym_ord, WORD obf_ord);</div>
<div class="line"><a name="l00363"></a><span class="lineno"> 363</span>  </div>
<div class="line"><a name="l00373"></a><span class="lineno"> 373</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> obf_sym(<span class="keywordtype">string</span> dll_name, WORD sym_ord, <span class="keywordtype">string</span> obf_name);</div>
<div class="line"><a name="l00374"></a><span class="lineno"> 374</span>  </div>
<div class="line"><a name="l00383"></a><span class="lineno"> 383</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> unobf_sym(<span class="keywordtype">string</span> dll_name, <span class="keywordtype">string</span> sym_name);</div>
<div class="line"><a name="l00384"></a><span class="lineno"> 384</span>  </div>
<div class="line"><a name="l00393"></a><span class="lineno"> 393</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> unobf_sym(<span class="keywordtype">string</span> dll_name, WORD sym_ord);</div>
<div class="line"><a name="l00394"></a><span class="lineno"> 394</span>  </div>
<div class="line"><a name="l00409"></a><span class="lineno"> 409</span>  <a class="code" href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a> generate(<span class="keywordtype">string</span> out_file);</div>
<div class="line"><a name="l00410"></a><span class="lineno"> 410</span> };</div>
<div class="line"><a name="l00411"></a><span class="lineno"> 411</span>  </div>
<div class="line"><a name="l00412"></a><span class="lineno"> 412</span> <span class="preprocessor">#endif // !COBF_HPP.</span></div>
</div><!-- fragment --></div><!-- contents -->
</div><!-- doc-content -->
<div class="ttc" id="aclasscobf_html"><div class="ttname"><a href="classcobf.html">cobf</a></div><div class="ttdef"><b>Definition:</b> <a href="cobf_8hpp_source.html#l00025">cobf.hpp:26</a></div></div>
<div class="ttc" id="autils_8hpp_html"><div class="ttname"><a href="utils_8hpp.html">utils.hpp</a></div></div>
<div class="ttc" id="ashellcode_8hpp_html"><div class="ttname"><a href="shellcode_8hpp.html">shellcode.hpp</a></div></div>
<div class="ttc" id="autils_8hpp_html_a420d571bdf7fb85bb7d45320e10f3522"><div class="ttname"><a href="utils_8hpp.html#a420d571bdf7fb85bb7d45320e10f3522">cobf_error</a></div><div class="ttdeci">cobf_error</div><div class="ttdef"><b>Definition:</b> <a href="utils_8hpp_source.html#l00015">utils.hpp:15</a></div></div>
<!-- start footer part -->
<div id="nav-path" class="navpath"><!-- id is needed for treeview function! -->
<ul>
<li class="navelem"><a class="el" href="dir_d44c64559bbebec7f509842c48db8b23.html">include</a></li><li class="navelem"><a class="el" href="cobf_8hpp.html">cobf.hpp</a></li>
<li class="footer">Generated by <a href="http://www.doxygen.org/index.html"><img class="footer" src="doxygen.svg" width="104" height="31" alt="doxygen"/></a> 1.8.20 </li>
</ul>
</div>
</body>
</html>