mirror of
https://github.com/quasar/Quasar.git
synced 2026-04-25 23:35:58 +03:00
[GH-ISSUE #436] pupy Explit & QuasarRAT C# ClassLibrary DLL INJECTION POSSIBLE? #222
Labels
No labels
bug
bug
cant-reproduce
discussion
duplicate
easy
enhancement
help wanted
improvement
invalid
need more info
pull-request
question
wont-add
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/Quasar#222
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @kainpark7894 on GitHub (Mar 29, 2016).
Original GitHub issue: https://github.com/quasar/Quasar/issues/436
QuasarRAT C# ClassLibrary DLL INJECTION POSSIBLE?
Default -> C# Client.exe -> Bulid Client.bin PE File
My Class Library Compile DLL ->Explorer.exe and Anyway 32bit&64bit DLL injection No execute Code
Hide injection Client.Bin -> DLL comfile Possible?
ex) reflective dll injection
https://github.com/dismantl/ImprovedReflectiveDLLInjection
@MK73DS commented on GitHub (Apr 21, 2016):
Does that mean that the client will launch as administrator when explorer.exe is launched ?
@kainpark7894 commented on GitHub (Apr 23, 2016):
pe format file taskmgr.exe View No Hidden
but dll format file Reflective INJECTION Hide Code injection(explorer.exe,iexplorer.exe,etc system File)
C# file Reflective Injection impossible? or Hide Client.exe -> DLL Injection What support?
@0xE232FE commented on GitHub (Aug 30, 2016):
What about System Integritychecks. Change explorer.exe and run the sfc /scannow command from commandprompt. The modified explorer.exe will be replaced over the original one.
If you want to gain Administration privilage try to figure out which Antivirus Programm the client uses and give him an Update. Remote Execute an Loader Programm that gain Administration privilage, Download the Latest version of the Virusscanner and Fake an important Update of the already installed Virusscanner. Once you have got Admin prviliage with your Loader you can modify the Privilage of Quasar at the same time. So the victim doesn't know whats going on ;-) and might give you admin privialge. Even if the client cancel the installtion after the admin priviallage you already modfied the privilage of Quasar and the Setup is only a side effect. ;-)