INNER CODE UNIT · C++

nt_headers

stivenhacker/GhostStrike · GhostStrike.cpp:90

    PIMAGE_NT_HEADERS nt_headers = (PIMAGE_NT_HEADERS)((BYTE*)module + dos_header->e_lfanew);
    PIMAGE_EXPORT_DIRECTORY export_dir = (PIMAGE_EXPORT_DIRECTORY)((BYTE*)module + nt_headers->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
    DWORD* functions = (DWORD*)((BYTE*)module + export_dir->AddressOfFunctions);
    WORD* ordinals = (WORD*)((BYTE*)module + export_dir->AddressOfNameOrdinals);
    DWORD* names = (DWORD*)((BYTE*)module + export_dir->AddressOfNames);

    // Loop through the export table to find the function by its hash.
    for (DWORD i = 0; i < export_dir->NumberOfNames; ++i) {
        const char* func_name = (const char*)((BYTE*)module + names[i]);
        if (hash_function(func_name) == function_hash) {
            return (FARPROC)((BYTE*)module + functions[ordinals[i]]);
        }
    }

    std::cerr << "Error retrieving the function address.\n";
    exit(EXIT_FAILURE);
}

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…