Advertisement
Guest User

Untitled

a guest
May 25th, 2019
85
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.97 KB | None | 0 0
  1. { Game : KSP_x64.exe
  2. Version:
  3. Date : 2019-05-25
  4. Author : Zach
  5.  
  6. This script does blah blah blah
  7. }
  8.  
  9. [ENABLE]
  10.  
  11. aobscanmodule(INJECT,KSP_x64.exe,89 81 F8 00 00 00 C3 CC CC CC CC CC CC CC CC CC) // should be unique
  12. alloc(newmem,$1000,"KSP_x64.exe"+4E2ADC)
  13.  
  14. label(code)
  15. label(return)
  16.  
  17. newmem:
  18.  
  19. code:
  20. mov [rcx+000000F8],eax
  21. jmp return
  22.  
  23. INJECT:
  24. jmp newmem
  25. nop
  26. return:
  27. registersymbol(INJECT)
  28.  
  29. [DISABLE]
  30.  
  31. INJECT:
  32. db 89 81 F8 00 00 00
  33.  
  34. unregistersymbol(INJECT)
  35. dealloc(newmem)
  36.  
  37. {
  38. // ORIGINAL CODE - INJECTION POINT: "KSP_x64.exe"+4E2ADC
  39.  
  40. "KSP_x64.exe"+4E2AB3: F3 0F 11 41 58 - movss [rcx+58],xmm0
  41. "KSP_x64.exe"+4E2AB8: F3 0F 10 81 F8 00 00 00 - movss xmm0,[rcx+000000F8]
  42. "KSP_x64.exe"+4E2AC0: 0F 2F D0 - comiss xmm2,xmm0
  43. "KSP_x64.exe"+4E2AC3: F3 0F 11 44 24 10 - movss [rsp+10],xmm0
  44. "KSP_x64.exe"+4E2AC9: 76 0A - jna KSP_x64.exe+4E2AD5
  45. "KSP_x64.exe"+4E2ACB: 8B 41 48 - mov eax,[rcx+48]
  46. "KSP_x64.exe"+4E2ACE: 89 81 F8 00 00 00 - mov [rcx+000000F8],eax
  47. "KSP_x64.exe"+4E2AD4: C3 - ret
  48. "KSP_x64.exe"+4E2AD5: 48 8D 44 24 10 - lea rax,[rsp+10]
  49. "KSP_x64.exe"+4E2ADA: 8B 00 - mov eax,[rax]
  50. // ---------- INJECTING HERE ----------
  51. "KSP_x64.exe"+4E2ADC: 89 81 F8 00 00 00 - mov [rcx+000000F8],eax
  52. // ---------- DONE INJECTING ----------
  53. "KSP_x64.exe"+4E2AE2: C3 - ret
  54. "KSP_x64.exe"+4E2AE3: CC - int 3
  55. "KSP_x64.exe"+4E2AE4: CC - int 3
  56. "KSP_x64.exe"+4E2AE5: CC - int 3
  57. "KSP_x64.exe"+4E2AE6: CC - int 3
  58. "KSP_x64.exe"+4E2AE7: CC - int 3
  59. "KSP_x64.exe"+4E2AE8: CC - int 3
  60. "KSP_x64.exe"+4E2AE9: CC - int 3
  61. "KSP_x64.exe"+4E2AEA: CC - int 3
  62. "KSP_x64.exe"+4E2AEB: CC - int 3
  63. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement