Technique revise

BCD - Code Caves

 

1.0 Preparing Code Caves

1.1 Finding Code Caves

┌──(kali㉿hfc84)-[~/tools/develop/Cminer]
└─$ ./Cminer ~/tmp/PUTTY.EXE
 
[#] Cave 2                                          
[*] Section: .rsrc                                  
[*] Cave Size: 4027 byte.                           
[*] Start Address: 0x80005654                       
[*] End Address: 0x8000660f                         
[*] File Ofset: 0xd4855

1.2 Preperations

  1. Open CFF Explorer
  2. Section Headers
  3. .rsrc
  4. Set section flags to RWX and Code
  5. Save the file

3.0 Payload

3.1 Reverse Shell Analysis

References