2.7 Example of Injection of a Software
201
Fig. 2.54 Final changes at the end of the code
By placing instructions POPFD and POPAD at the end of the shellcode, we will
recover all previously saved registers from the stack in the same order. After recovering the registers, it is necessary to remember another nuance. During interception
of the execution thread, PUSH 467C7C was replaced with JMP 0x47A478 in order
to redirect execution to the code cave. If the instruction PUSH 467C7C is placed at
the end of the code, the intercepted instruction will also be recovered. Now it’s time
to go back to the function that redirected execution to the code cave with the help of
inserting the JMP 0x41CB73 instruction. The end of the resulting code must look as
shown in Fig. 2.54.
Now, select all modified and pasted instructions, right-click, and copy them into
the executable. This operation must be repeated for every modified instruction. After
all instructions are copied and saved in the file, close the debugger and test the
resulting piece of art. If the execution goes without errors, the backdoor is ready to
be used.
In the end, the author of the work [23] recommends changing the resulting file
checksum in order to preserve authenticity and cause no suspicions (Fig. 2.55).
So, if all the above methods are used correctly, the final backdoor version will be
completely invisible (Fig. 2.56). In conclusion, let us consider certain measures of
Fig. 2.55 Changing the checksum in the PE file editor
201
Fig. 2.54 Final changes at the end of the code
By placing instructions POPFD and POPAD at the end of the shellcode, we will
recover all previously saved registers from the stack in the same order. After recovering the registers, it is necessary to remember another nuance. During interception
of the execution thread, PUSH 467C7C was replaced with JMP 0x47A478 in order
to redirect execution to the code cave. If the instruction PUSH 467C7C is placed at
the end of the code, the intercepted instruction will also be recovered. Now it’s time
to go back to the function that redirected execution to the code cave with the help of
inserting the JMP 0x41CB73 instruction. The end of the resulting code must look as
shown in Fig. 2.54.
Now, select all modified and pasted instructions, right-click, and copy them into
the executable. This operation must be repeated for every modified instruction. After
all instructions are copied and saved in the file, close the debugger and test the
resulting piece of art. If the execution goes without errors, the backdoor is ready to
be used.
In the end, the author of the work [23] recommends changing the resulting file
checksum in order to preserve authenticity and cause no suspicions (Fig. 2.55).
So, if all the above methods are used correctly, the final backdoor version will be
completely invisible (Fig. 2.56). In conclusion, let us consider certain measures of
Fig. 2.55 Changing the checksum in the PE file editor
