- Joined
- Jan 8, 2019
- Messages
- 56,623
- Solutions
- 2
- Reputation
- 32
- Reaction score
- 100,455
- Points
- 2,313
- Credits
- 32,750
6 Years of Service
76%

Details:
no crt functions imported
syscall unhooking using KnownDllUnhook
api hashing using Rotr32 hashing algo
payload encryption using rc4 - payload is saved in .rsrc
process injection - targetting 'SettingSyncHost.exe'
ppid spoofing & blockdlls policy using NtCreateUserProcess
stealthy remote process injection - chunking
using debugging & NtQueueApcThread for payload execution
To see this hidden content, you must like this content.