-
Notifications
You must be signed in to change notification settings - Fork 1
/
AntiDebug.go
74 lines (63 loc) · 1.58 KB
/
AntiDebug.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
package github.com/9dl/SecureX
import (
"log"
"os"
"os/exec"
"strings"
"syscall"
)
var blacklisted = []string{
"processh", "debug", "debugger", "hacker", "inject", "dump",
"dumper", "deobfs", "deobfuscator", "dnspy", "de4dot", "dbg",
"string", "decrypt", "decryptor", "detect it easy", "die",
"unpack", "unpacker", "http",
}
func AntiDebugRun() {
for {
if isDebuggerAttached() {
log.Println("Debugger detected. Terminating...")
os.Exit(0)
}
processList, err := getProcessList()
if err != nil {
log.Fatal(err)
}
killBlacklistedProcesses(processList)
}
}
func getProcessList() (string, error) {
processes, err := exec.Command("tasklist").Output()
if err != nil {
return "", err
}
return string(processes), nil
}
func killBlacklistedProcesses(processList string) {
for _, blacklistedProcess := range blacklisted {
if strings.Contains(processList, blacklistedProcess) {
err := killProcess(blacklistedProcess)
if err != nil {
log.Fatal(err)
}
}
}
}
func killProcess(processName string) error {
cmd := exec.Command("taskkill", "/F", "/IM", processName)
cmd.Stdout = os.Stdout
cmd.Stderr = os.Stderr
return cmd.Run()
}
func isDebuggerAttached() bool {
kernel32, err := syscall.LoadLibrary("kernel32.dll")
if err != nil {
return false
}
defer syscall.FreeLibrary(kernel32)
isDebuggerPresent, err := syscall.GetProcAddress(kernel32, "IsDebuggerPresent")
if err != nil {
return false
}
ret, _, _ := syscall.Syscall(uintptr(isDebuggerPresent), 0, 0, 0, 0)
return ret != 0
}