Post

MalDevEdr

MalDevEdr

What is it?

A DLL that acts as a miniature EDR — inject it into any process and it installs a hook on NtProtectVirtualMemory using the MinHook library. Every time the target process tries to change memory permissions, the hook fires, dumps the memory contents to a console, and optionally terminates the process depending on what permissions were requested.

How it works

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
DLL injected into target process
        │
        │ DLL_PROCESS_ATTACH
        ▼
CreateThread(InstallTheHookviaMinHook)
        │
        ▼
InstallTheHookviaMinHook():
  CreateOutputConsole()
    └─ GUI process: FreeConsole() + AllocConsole()
    └─ CLI process: GetStdHandle(STD_OUTPUT_HANDLE)
  
  MH_Initialize()
  MH_CreateHookApi("NTDLL.DLL", "NtProtectVirtualMemory",
                    Hooked_NtProtectVirtualMemory,
                    &g_NtProtectVirtualMemory)
  MH_EnableHook(MH_ALL_HOOKS)
  → Hook installed. Every VirtualProtect call in the process now
    routes through our function first.


Every call to NtProtectVirtualMemory:
        │
        ▼
Hooked_NtProtectVirtualMemory():
  Print: address + size of memory being protected
        │
        ├─ NewAccessProtection & PAGE_EXECUTE_READWRITE?
        │    → [DETECTED] print + BlockExecution(Terminate=TRUE)
        │       → dump memory as hex to console
        │       → MessageBox "Terminating..." + ExitProcess(1)
        │
        ├─ NewAccessProtection & PAGE_EXECUTE_READ?
        │    → [DETECTED] print + BlockExecution(Terminate=FALSE)
        │       → dump memory as hex to console
        │       → continue execution (just logged, not killed)
        │
        └─ call g_NtProtectVirtualMemory()  ← original function
           (forward to real ntdll regardless)


DLL_PROCESS_DETACH:
  ProcessDetachRoutine()
  MH_DisableHook(MH_ALL_HOOKS)
  MH_Uninitialize()

The compile-time switch TARGET_CLI_PROCESSES vs TARGET_GUI_PROCESSES controls how the console is allocated. CLI processes already have stdout, so GetStdHandle is enough. GUI processes (no console window) need FreeConsole + AllocConsole first to create one.

PAGE_EXECUTE_READWRITE gets the hard response (terminate) because that’s the classic injection signature — memory that’s simultaneously writable and executable is the standard pattern for shellcode allocation. PAGE_EXECUTE_READ gets logged but not killed because that’s a normal permission for code sections that just got executed.

The commented-out MH_RemoveHook in BlockExecution is a curiosity — the intent was presumably to unhook before terminating, but it was left out, so the hook is still installed in the process (briefly) before ExitProcess kills everything.

Console.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
#include <Windows.h>
#include <stdio.h>

#include "Common.h"


// if injecting the dll into a cli process
// if not, then comment it:

#define TARGET_CLI_PROCESSES	

#ifndef TARGET_CLI_PROCESSES
#define TARGET_GUI_PROCESSES
#endif // !TARGET_CLI_PROCESSES




HANDLE		g_hConsole		= NULL;

// create a console screen to write to
HANDLE CreateOutputConsole() {

	if (g_hConsole != NULL){
		return g_hConsole;
	}

#ifdef TARGET_GUI_PROCESSES
	
	if (!FreeConsole()) {
		return NULL;
	}
	if (!AllocConsole()) {
		return NULL;
	}

#endif // TARGET_GUI_PROCESSES

	if ((g_hConsole = GetStdHandle(STD_OUTPUT_HANDLE)) == NULL) {
		return NULL;
	}

	return g_hConsole;
}






VOID ReportError(LPCSTR lpFunctionName, DWORD dwError) {

	PRINT("[!] \"%s\" Failed With Error : %d \n", lpFunctionName, dwError);
	MessageBoxA(NULL, "", "", MB_OK);
}




DllMain.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
#include <Windows.h>
#include <stdio.h>
#include "Common.h"





BOOL APIENTRY DllMain (HMODULE hModule, DWORD dwReason, LPVOID lpReserved){


    HANDLE hThread = NULL;


    switch (dwReason)
    {
        case DLL_PROCESS_ATTACH: {
           hThread = CreateThread(NULL, NULL, &InstallTheHookviaMinHook, NULL, NULL, NULL); //install the hook
           if (hThread)
               CloseHandle(hThread);
           break;
        };

        case DLL_PROCESS_DETACH: {
            ProcessDetachRoutine(); // remove the hooks
            break;
        };
    }

    return TRUE;
}


Hook.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
#include <Windows.h>
#include <stdio.h>

#include "MinHook.h"
#include "Common.h"


#ifdef _WIN64
#pragma comment(lib, "minhook.x64.lib")
#elif _WIN32
#pragma comment(lib, "minhook.x32.lib")
#endif




fnNtProtectVirtualMemory	g_NtProtectVirtualMemory	= NULL;	// original NtProtectVirtualMemory to call in the hook function
PVOID						pNtProtectVirtualMemory		= NULL;	// address of the NtProtectVirtualMemory function


// what will be executed instead of NtProtectVirtualMemory
NTSTATUS WINAPI Hooked_NtProtectVirtualMemory(
	HANDLE      ProcessHandle,
	PVOID*		BaseAddress,
	PULONG      NumberOfBytesToProtect,
	ULONG       NewAccessProtection,
	PULONG      OldAccessProtection
){


	PRINT("[#] NtProtectVirtualMemory At [ 0x%p ] Of Size [ %d ] \n", (PVOID)*BaseAddress, (unsigned int)*NumberOfBytesToProtect);
	
	// if PAGE_EXECUTE_READWRITE = dump memory + terminate
	if ((NewAccessProtection & PAGE_EXECUTE_READWRITE) == PAGE_EXECUTE_READWRITE) {
		PRINT("\t\t\t<<<!>>> [DETECTED] PAGE_EXECUTE_READWRITE [DETECTED] <<<!>>> \n");
		BlockExecution((PBYTE)*BaseAddress, (SIZE_T)*NumberOfBytesToProtect, TRUE);
	}

	// if PAGE_EXECUTE_READWRITE = dump memory + continue
	if ((NewAccessProtection & PAGE_EXECUTE_READ) == PAGE_EXECUTE_READ) {
		PRINT("\t\t\t<<<!>>> [DETECTED] PAGE_EXECUTE_READ [DETECTED] <<<!>>> \n");
		BlockExecution((PBYTE)*BaseAddress, (SIZE_T)*NumberOfBytesToProtect, FALSE);
	}

	// return the expected output
	return  g_NtProtectVirtualMemory(ProcessHandle, BaseAddress, NumberOfBytesToProtect, NewAccessProtection, OldAccessProtection);
}



// hooking NtProtectVirtualMemory using minhook library
BOOL InstallTheHookviaMinHook() {


	LONG	MinHookErr = MH_OK;

	pNtProtectVirtualMemory = GetProcAddress(GetModuleHandleW(TEXT("NTDLL.DLL")), "NtProtectVirtualMemory");

	if (CreateOutputConsole() == NULL) {
		MessageBoxA(NULL, "Failed To Allocate Console", "ERROR", MB_OK | MB_ICONERROR);
		return FALSE;
	}

	PRINT("\n\t\t\t <><><><><><>[ MALDEV ACAD EDR INJECTED ]<><><><><><> \n\n");


	if ((MinHookErr = MH_Initialize()) != MH_OK) {
		
		("MH_Initialize", MinHookErr);
		return FALSE;
	}

	if (((MinHookErr = MH_CreateHookApi(TEXT("NTDLL.DLL"), "NtProtectVirtualMemory", Hooked_NtProtectVirtualMemory, (LPVOID*)&g_NtProtectVirtualMemory) != MH_OK))) {
		ReportError("MH_CreateHookApi", MinHookErr);
		return FALSE;
	}

	if ((MinHookErr = MH_EnableHook(MH_ALL_HOOKS)) != MH_OK) {
		ReportError("MH_EnableHook", MinHookErr);
		return FALSE;
	}



	return TRUE;
}


// used to dump memory at `pAddress` of size `sSize`
// terminates the process if `Terminate` is true
VOID BlockExecution(PBYTE pAddress, SIZE_T sSize, BOOL Terminate) {

	PRINT("\n\t------------------------------------[ MEMORY DUMP ]------------------------------------\n\n");
	for (int i = 0; i < sSize; i++) {
		if (i % 16 == 0) {
			PRINT("\n\t\t");
		}
		PRINT(" %02X", pAddress[i]);
	}
	PRINT("\n\n\t------------------------------------[ MEMORY DUMP ]------------------------------------\n\n");

	if (Terminate){
		/*
		LONG	MinHookErr = MH_OK;

		if ((MinHookErr = MH_RemoveHook(pNtProtectVirtualMemory)) != MH_OK) {
			ReportError("MH_RemoveHook", MinHookErr);
		}
		*/
		MessageBoxA(NULL, "Terminating The Process ... ", "Maldev Edr", MB_OKCANCEL | MB_ICONERROR);
		ExitProcess(1);
	}
}



// unhooking the installed hook on NtProtectVirtualMemory
VOID ProcessDetachRoutine() {

	LONG	MinHookErr = MH_OK;

	if ((MinHookErr = MH_DisableHook(MH_ALL_HOOKS)) != MH_OK) {
		ReportError("MH_DisableHook", MinHookErr);
	}

	if ((MinHookErr = MH_Uninitialize()) != MH_OK) {
		ReportError("MH_Uninitialize", MinHookErr);
	}

}








Common.h

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
#include <Windows.h>


#ifndef HOOKS_H
#define HOOKS_H



HANDLE CreateOutputConsole();
VOID ReportError(LPCSTR lpFunctionName, DWORD dwError);

// print to screen (act as printf)
#define PRINT( STR, ... )                                                                  \
    if (1) {                                                                                \
        LPSTR buf = (LPSTR)HeapAlloc( GetProcessHeap(), HEAP_ZERO_MEMORY, 1024 );           \
        if ( buf != NULL ) {                                                                \
            int len = wsprintfA( buf, STR, __VA_ARGS__ );                                   \
            WriteConsoleA( CreateOutputConsole(), buf, len, NULL, NULL );                   \
            HeapFree( GetProcessHeap(), 0, buf );                                           \
        }                                                                                   \
    }  



typedef NTSTATUS(NTAPI* fnNtProtectVirtualMemory)(
    IN		HANDLE      ProcessHandle,
    IN OUT	PVOID*      BaseAddress,
    IN OUT	PULONG      NumberOfBytesToProtect,
    IN		ULONG       NewAccessProtection,
    OUT		PULONG      OldAccessProtection
    );



BOOL InstallTheHookviaMinHook();
VOID ProcessDetachRoutine();
VOID BlockExecution(PBYTE pAddress, SIZE_T sSize, BOOL Terminate);


#endif // !HOOKS_H

MinHook.h

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
/*
 *  MinHook - The Minimalistic API Hooking Library for x64/x86
 *  Copyright (C) 2009-2017 Tsuda Kageyu.
 *  All rights reserved.
 *
 *  Redistribution and use in source and binary forms, with or without
 *  modification, are permitted provided that the following conditions
 *  are met:
 *
 *   1. Redistributions of source code must retain the above copyright
 *      notice, this list of conditions and the following disclaimer.
 *   2. Redistributions in binary form must reproduce the above copyright
 *      notice, this list of conditions and the following disclaimer in the
 *      documentation and/or other materials provided with the distribution.
 *
 *  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
 *  "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
 *  TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
 *  PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER
 *  OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
 *  EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
 *  PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
 *  PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
 *  LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
 *  NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
 *  SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
 */

#pragma once

#if !(defined _M_IX86) && !(defined _M_X64) && !(defined __i386__) && !(defined __x86_64__)
    #error MinHook supports only x86 and x64 systems.
#endif

#include <windows.h>

// MinHook Error Codes.
typedef enum MH_STATUS
{
    // Unknown error. Should not be returned.
    MH_UNKNOWN = -1,

    // Successful.
    MH_OK = 0,

    // MinHook is already initialized.
    MH_ERROR_ALREADY_INITIALIZED,

    // MinHook is not initialized yet, or already uninitialized.
    MH_ERROR_NOT_INITIALIZED,

    // The hook for the specified target function is already created.
    MH_ERROR_ALREADY_CREATED,

    // The hook for the specified target function is not created yet.
    MH_ERROR_NOT_CREATED,

    // The hook for the specified target function is already enabled.
    MH_ERROR_ENABLED,

    // The hook for the specified target function is not enabled yet, or already
    // disabled.
    MH_ERROR_DISABLED,

    // The specified pointer is invalid. It points the address of non-allocated
    // and/or non-executable region.
    MH_ERROR_NOT_EXECUTABLE,

    // The specified target function cannot be hooked.
    MH_ERROR_UNSUPPORTED_FUNCTION,

    // Failed to allocate memory.
    MH_ERROR_MEMORY_ALLOC,

    // Failed to change the memory protection.
    MH_ERROR_MEMORY_PROTECT,

    // The specified module is not loaded.
    MH_ERROR_MODULE_NOT_FOUND,

    // The specified function is not found.
    MH_ERROR_FUNCTION_NOT_FOUND
}
MH_STATUS;

// Can be passed as a parameter to MH_EnableHook, MH_DisableHook,
// MH_QueueEnableHook or MH_QueueDisableHook.
#define MH_ALL_HOOKS NULL

#ifdef __cplusplus
extern "C" {
#endif

    // Initialize the MinHook library. You must call this function EXACTLY ONCE
    // at the beginning of your program.
    MH_STATUS WINAPI MH_Initialize(VOID);

    // Uninitialize the MinHook library. You must call this function EXACTLY
    // ONCE at the end of your program.
    MH_STATUS WINAPI MH_Uninitialize(VOID);

    // Creates a hook for the specified target function, in disabled state.
    // Parameters:
    //   pTarget     [in]  A pointer to the target function, which will be
    //                     overridden by the detour function.
    //   pDetour     [in]  A pointer to the detour function, which will override
    //                     the target function.
    //   ppOriginal  [out] A pointer to the trampoline function, which will be
    //                     used to call the original target function.
    //                     This parameter can be NULL.
    MH_STATUS WINAPI MH_CreateHook(LPVOID pTarget, LPVOID pDetour, LPVOID *ppOriginal);

    // Creates a hook for the specified API function, in disabled state.
    // Parameters:
    //   pszModule   [in]  A pointer to the loaded module name which contains the
    //                     target function.
    //   pszProcName [in]  A pointer to the target function name, which will be
    //                     overridden by the detour function.
    //   pDetour     [in]  A pointer to the detour function, which will override
    //                     the target function.
    //   ppOriginal  [out] A pointer to the trampoline function, which will be
    //                     used to call the original target function.
    //                     This parameter can be NULL.
    MH_STATUS WINAPI MH_CreateHookApi(
        LPCWSTR pszModule, LPCSTR pszProcName, LPVOID pDetour, LPVOID *ppOriginal);

    // Creates a hook for the specified API function, in disabled state.
    // Parameters:
    //   pszModule   [in]  A pointer to the loaded module name which contains the
    //                     target function.
    //   pszProcName [in]  A pointer to the target function name, which will be
    //                     overridden by the detour function.
    //   pDetour     [in]  A pointer to the detour function, which will override
    //                     the target function.
    //   ppOriginal  [out] A pointer to the trampoline function, which will be
    //                     used to call the original target function.
    //                     This parameter can be NULL.
    //   ppTarget    [out] A pointer to the target function, which will be used
    //                     with other functions.
    //                     This parameter can be NULL.
    MH_STATUS WINAPI MH_CreateHookApiEx(
        LPCWSTR pszModule, LPCSTR pszProcName, LPVOID pDetour, LPVOID *ppOriginal, LPVOID *ppTarget);

    // Removes an already created hook.
    // Parameters:
    //   pTarget [in] A pointer to the target function.
    MH_STATUS WINAPI MH_RemoveHook(LPVOID pTarget);

    // Enables an already created hook.
    // Parameters:
    //   pTarget [in] A pointer to the target function.
    //                If this parameter is MH_ALL_HOOKS, all created hooks are
    //                enabled in one go.
    MH_STATUS WINAPI MH_EnableHook(LPVOID pTarget);

    // Disables an already created hook.
    // Parameters:
    //   pTarget [in] A pointer to the target function.
    //                If this parameter is MH_ALL_HOOKS, all created hooks are
    //                disabled in one go.
    MH_STATUS WINAPI MH_DisableHook(LPVOID pTarget);

    // Queues to enable an already created hook.
    // Parameters:
    //   pTarget [in] A pointer to the target function.
    //                If this parameter is MH_ALL_HOOKS, all created hooks are
    //                queued to be enabled.
    MH_STATUS WINAPI MH_QueueEnableHook(LPVOID pTarget);

    // Queues to disable an already created hook.
    // Parameters:
    //   pTarget [in] A pointer to the target function.
    //                If this parameter is MH_ALL_HOOKS, all created hooks are
    //                queued to be disabled.
    MH_STATUS WINAPI MH_QueueDisableHook(LPVOID pTarget);

    // Applies all queued changes in one go.
    MH_STATUS WINAPI MH_ApplyQueued(VOID);

    // Translates the MH_STATUS to its name as a string.
    const char * WINAPI MH_StatusToString(MH_STATUS status);

#ifdef __cplusplus
}
#endif

This post is licensed under CC BY 4.0 by the author.
Source code: MalDevEdr