Jump to content
YOUR-AD-HERE
HOSTING
TOOLS

Locked TerraLdr - A Payload Loader Designed With Advanced Evasion Features


itsMe

Recommended Posts

This is the hidden content, please

Details:

    no crt functions imported
    syscall unhooking using KnownDllUnhook
    api hashing using Rotr32 hashing algo
    payload encryption using rc4 - payload is saved in .rsrc
    process injection - targetting 'SettingSyncHost.exe'
    ppid spoofing & blockdlls policy using NtCreateUserProcess
    stealthy remote process injection - chunking
    using debugging & NtQueueApcThread for payload execution

This is the hidden content, please

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.