Skip to content

Instantly share code, notes, and snippets.

@adeii
Created January 4, 2024 18:41
Show Gist options
  • Save adeii/6bd6800eb8b8b44fe5bfda7aab48734c to your computer and use it in GitHub Desktop.
Save adeii/6bd6800eb8b8b44fe5bfda7aab48734c to your computer and use it in GitHub Desktop.
Chrome 117.0.5938.63 to Win 7
chrome.exe
==========
PE.ImportTable: USER32.dll -> USER64.dll, KERNEL32.dll -> KERNEL64.dll, USERENV.dll -> USERENX.dll,
sandbox init props:
clear digital sign:
00 44 31 00 20 29 00 00 00 80 32 00 58 25 00 00 --> 00 00 00 00 00 00 00 00 00 80 32 00 58 25 00 00
120-Security Directory RVA / Size --> 00000000
---
40c10: 15 B3 D8 24 00 85 C0 74 14 FF CF 48 8B 0E 48 85 --> 15 B3 D8 24 00 90 90 90 90 90 90 90 90 90 90 90
40c20: C9 75 72 B3 01 85 FF 0F 85 2A 01 00 00 89 D8 48 --> 90 90 90 B3 01 90 90 90 90 90 90 90 90 89 D8 48
206240: 48 89 F9 E8 98 E7 00 00 84 DB 75 14 FF 15 CE 7D --> 48 89 F9 E8 98 E7 00 00 84 DB EB 14 FF 15 CE 7D
273b10: bprimitives -> xprimitives (hidden)
28d1b8: userenv -> userenx (hidden)
28f4a0: kernel32 -> kernel64
chrome_proxy.exe
=======================
clear digital sign:
120: 00 B6 29 00 A0 29 00 00 00 40 2B 00 70 20 --> 00 00 00 00 00 00 00 00 00 40 2B 00 70 20
import optional> kernel32, userenv, user32
chrome_elf.dll
==============
PE.ImportTable: KERNEL32.dll -> KERNEL64.dll
PE.DELAY_IMPORT:
clear digital sign:
120: 00 8A 12 00 A0 29 00 00 00 D0 13 00 B4 14 --> 00 00 00 00 00 00 00 00 00 D0 13 00 B4 14
11b5a0: bprimitives -> xprimitives (hidden)
12c240: kernel32 -> kernel64
chrome.dll
=================
PE.ImportTable: USER32.dll -> USER64.dll, KERNEL32.dll -> KERNEL64.dll, USERENV.dll -> USERENX.dll, WINHTTP.dll -> WINXTTP.dll,
clear digital sign:
120: 00 08 73 0D 20 29 00 00 00 50 88 0D 60 D5 16 00 --> 00 00 00 00 00 00 00 00 00 50 88 0D 60 D5 16 00
120-Security Directory RVA / Size --> 00000000
1767C0:
C1 30 C1 0F 84 0E 01 00 00 4C 8B BC 24 C0 00 00 --> C1 30 C1 90 90 90 90 90 90 4C 8B BC 24 C0 00 00
100B8A0:
00 00 4C 89 F1 BA 01 00 00 00 41 B8 0F 00 00 10 --> 00 00 4C 89 F1 BA 01 00 00 00 41 B8 0F 00 00 00
100B8B0:
4D 89 F9 FF 15 7F C3 00 0C 85 C0 0F 85 20 01 00 --> 4D 89 F9 FF 15 7F C3 00 0C 85 C0 0F 85 20 01 00
1547150:
00 48 85 C0 0F 84 C9 00 00 00 83 78 38 01 0F 85 --> 00 48 85 C0 E9 CA 00 00 00 90 83 78 38 01 0F 85
BB9CB40: bprimitives -> xprimitives (hidden)
c062f20: 8D EE 3A 9A F7 B7 32 EC C3 41 1B 9A BB D3 6A 46 --> 8D EE 3A 9A F7 B7 32 EC 5A EE 59 B8 38 D8 5B 4B
c062f30: 87 FC FE 67 55 6A 3B 65 43 00 68 00 72 00 6F 00 --> A2 E8 1A DC 7D 93 DB 48 43 00 68 00 72 00 6F 00
c6b1306: bprimitives -> xprimitives (hidden)
cf2b550: user32 -> user64
cf2b577: mfplat -> xfplat
cf31310: kernel32 -> kernel64
cf31358: userenv -> userenx
cf313c3: winhttp -> winxttp
chrome_wer.exe
==============
120: 00 B6 29 00 A0 29 00 00 00 40 2B 00 70 20 00 00 --> 00 00 00 00 00 00 00 00 00 40 2B 00 70 20 00 00
120-Security Directory RVA / Size --> 00000000
import optional> kernel32
chrome_paw_launcher.exe
==============
120: 00 B6 29 00 A0 29 00 00 00 40 2B 00 70 20 00 00 --> 00 00 00 00 00 00 00 00 00 40 2B 00 70 20 00 00
120-Security Directory RVA / Size --> 00000000
import optional> kernel32, userenv, user32
* tested, works.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment