获取父进程路径

获取父进程路径

获取父进程路径,可用于反沙箱

#include <Windows.h>
#include <tlhelp32.h>
#include <stdio.h>

DWORD GetParentPID(DWORD pid)
{
	DWORD ppid = 0;
	PROCESSENTRY32W processEntry = { 0 };
	processEntry.dwSize = sizeof(PROCESSENTRY32W);
	HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
	if (Process32FirstW(hSnapshot, &processEntry))
	{
		do
		{
			if (processEntry.th32ProcessID == pid)
			{
				ppid = processEntry.th32ParentProcessID;
				break;
			}
		} while (Process32NextW(hSnapshot, &processEntry));
	}
	CloseHandle(hSnapshot);
	return ppid;
}

int main() {
	DWORD parentPid = GetParentPID(GetCurrentProcessId());
	WCHAR parentName[MAX_PATH + 1];
	DWORD dwParentName = MAX_PATH;
	HANDLE hParent = OpenProcess(PROCESS_QUERY_INFORMATION, FALSE, parentPid);
	QueryFullProcessImageNameW(hParent, 0, parentName, &dwParentName); // another way to get process name is to use 'Toolhelp32Snapshot'
	//CharUpperW(parentName);
	wprintf(L"parentName: %ls\n", parentName);
	if (!wcsstr(parentName, L"explorer.exe")) {
		wprintf_s(L"Do nothing.\n");
		//return;
	} else
		wprintf_s(L"Now hacking...\n");

	getchar();
	return 0;
}

由于QueryFullProcessImageNameW只支持Windows Vista及以上的系统,所以用GetProcessImageFileNameW换一下以兼容xp:

#include <Windows.h>
#include <tlhelp32.h>
#include <psapi.h>
#include <stdio.h>
#pragma comment(lib,"Psapi.lib")

DWORD GetParentPID(DWORD pid)
{
	DWORD ppid = 0;
	PROCESSENTRY32W processEntry = { 0 };
	processEntry.dwSize = sizeof(PROCESSENTRY32W);
	HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
	if (Process32FirstW(hSnapshot, &processEntry))
	{
		do
		{
			if (processEntry.th32ProcessID == pid)
			{
				ppid = processEntry.th32ParentProcessID;
				break;
			}
		} while (Process32NextW(hSnapshot, &processEntry));
	}
	CloseHandle(hSnapshot);
	return ppid;
}

int main() {
	DWORD parentPid = GetParentPID(GetCurrentProcessId());
	WCHAR parentName[MAX_PATH + 1];
	DWORD dwParentName = MAX_PATH;
	HANDLE hParent = OpenProcess(PROCESS_QUERY_INFORMATION, FALSE, parentPid);
	GetProcessImageFileNameW(hParent, parentName, dwParentName); // another way to get process name is to use 'Toolhelp32Snapshot'
	//CharUpperW(parentName);
	wprintf(L"parentName: %ls\n", parentName);
	if (!wcsstr(parentName, L"explorer.exe")) {
		wprintf_s(L"Do nothing.\n");
		//return;
	}
	else
		wprintf_s(L"Now hacking...\n");

	getchar();
	return 0;
}

当然也是可以用2次CreateToolhelp32Snapshot来兼容xp的:

#include <Windows.h>
#include <tlhelp32.h>
#include <stdio.h>

DWORD GetParentPID(DWORD pid)
{
	DWORD ppid = 0;
	PROCESSENTRY32W processEntry = { 0 };
	processEntry.dwSize = sizeof(PROCESSENTRY32W);
	HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
	if (Process32FirstW(hSnapshot, &processEntry))
	{
		do
		{
			if (processEntry.th32ProcessID == pid)
			{
				ppid = processEntry.th32ParentProcessID;
				break;
			}
		} while (Process32NextW(hSnapshot, &processEntry));
	}
	CloseHandle(hSnapshot);
	return ppid;
}

int main() {
	bool bDebugged = false;
	DWORD dwParentProcessId = GetParentPID(GetCurrentProcessId());

	PROCESSENTRY32 ProcessEntry = { 0 };
	ProcessEntry.dwSize = sizeof(PROCESSENTRY32W);

	HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, 0);
	if (Process32First(hSnapshot, &ProcessEntry))
	{
		do
		{
			if ((ProcessEntry.th32ProcessID == dwParentProcessId))
			{
				wprintf(L"parentName: %ls\n", ProcessEntry.szExeFile);
				if (!wcsstr(ProcessEntry.szExeFile, L"explorer.exe")) {
					bDebugged = true;
					break;
				}
			}
		} while (Process32Next(hSnapshot, &ProcessEntry));
	}

	CloseHandle(hSnapshot);

	if (bDebugged) {
		wprintf_s(L"Do nothing.\n");
		//return;
	}
	else
		wprintf_s(L"Now hacking...\n");

	getchar();
	return 0;
}

原链接:

  1. https://0xpat.github.io/Malware_development_part_2/
  2. https://bbs.pediy.com/thread-268528.htm

2021/4/20

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值