| Module Name |
|
| Full Name |
|
| EntryPoint |
System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Scope Name |
|
| Scope Type |
|
| Kind |
|
| Runtime Version |
|
| Tables Header Version |
|
| WinMD Version |
|
| Assembly Name |
|
| Assembly Version |
|
| Assembly Culture |
|
| Has PublicKey |
|
| PublicKey Token |
|
| Target Framework |
.NETFramework,Version=v4.8 |
| Total Strings |
|
| Main Method |
System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Main IL Instruction Count |
|
| Main IL |
newobj System.Void ProcessHollowing.Handler.CommandLineParser::.ctor()
stloc.0 <null>
ldloc.0 <null>
ldstr ProcessHollowing - PoC for Process Hollowing.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::SetTitle(System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr h
ldstr help
ldstr Displays this help message.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddFlag(System.Boolean,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr f
ldstr fake
ldnull <null>
ldstr Specifies fake command line.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr r
ldstr real
ldnull <null>
ldstr Specifies image path you want to execute.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr p
ldstr ppid
ldnull <null>
ldstr Specifies PPID for PPID Spoofing.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr w
ldstr window
ldstr Process Hollowing!!
ldstr Specifies window title. Default value is "Process Hollowing!!".
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldarg.0 <null>
callvirt System.String[] ProcessHollowing.Handler.CommandLineParser::Parse(System.String[])
pop <null>
ldloc.0 <null>
call System.Void ProcessHollowing.Handler.Execute::Run(ProcessHollowing.Handler.CommandLineParser)
leave.s IL_00B5: ret
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
leave.s IL_00B5: ret
ldloc.0 <null>
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::GetHelp()
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
leave.s IL_00B5: ret
ret <null>
|
| Info |
PE Detect: PeReader OK (file layout) |
| Info |
PDB Path: C:\Users\anogon\Downloads\TangledWinExec-main\TangledWinExec-main\ProcessHollowing\ProcessHollowing\obj\Release\ProcessHollowing.pdb
|
| Module Name |
|
| Full Name |
|
| EntryPoint |
System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Scope Name |
|
| Scope Type |
|
| Kind |
|
| Runtime Version |
|
| Tables Header Version |
|
| WinMD Version |
|
| Assembly Name |
|
| Assembly Version |
|
| Assembly Culture |
|
| Has PublicKey |
|
| PublicKey Token |
|
| Target Framework |
.NETFramework,Version=v4.8 |
| Total Strings |
|
| Main Method |
System.Void ProcessHollowing.ProcessHollowing::Main(System.String[]) |
| Main IL Instruction Count |
|
| Main IL |
newobj System.Void ProcessHollowing.Handler.CommandLineParser::.ctor()
stloc.0 <null>
ldloc.0 <null>
ldstr ProcessHollowing - PoC for Process Hollowing.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::SetTitle(System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr h
ldstr help
ldstr Displays this help message.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddFlag(System.Boolean,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr f
ldstr fake
ldnull <null>
ldstr Specifies fake command line.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr r
ldstr real
ldnull <null>
ldstr Specifies image path you want to execute.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr p
ldstr ppid
ldnull <null>
ldstr Specifies PPID for PPID Spoofing.
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldc.i4.0 <null>
ldstr w
ldstr window
ldstr Process Hollowing!!
ldstr Specifies window title. Default value is "Process Hollowing!!".
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::AddParameter(System.Boolean,System.String,System.String,System.String,System.String)
ldloc.0 <null>
ldarg.0 <null>
callvirt System.String[] ProcessHollowing.Handler.CommandLineParser::Parse(System.String[])
pop <null>
ldloc.0 <null>
call System.Void ProcessHollowing.Handler.Execute::Run(ProcessHollowing.Handler.CommandLineParser)
leave.s IL_00B5: ret
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
leave.s IL_00B5: ret
ldloc.0 <null>
callvirt System.Void ProcessHollowing.Handler.CommandLineParser::GetHelp()
callvirt System.String System.Exception::get_Message()
call System.Void System.Console::WriteLine(System.String)
leave.s IL_00B5: ret
ret <null>
|