• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

TerraLdr - A Payload Loader Designed With Advanced Evasion Features

Status
Not open for further replies.

itsMe

*KillmeMories*
Staff member
Administrator
Super Moderator
Hacker
Specter
Crawler
Shadow
Joined
Jan 8, 2019
Messages
56,623
Solutions
2
Reputation
32
Reaction score
100,455
Points
2,313
Credits
32,750
‎6 Years of Service‎
 
76%
198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png


Details:

    no crt functions imported
    syscall unhooking using KnownDllUnhook
    api hashing using Rotr32 hashing algo
    payload encryption using rc4 - payload is saved in .rsrc
    process injection - targetting 'SettingSyncHost.exe'
    ppid spoofing & blockdlls policy using NtCreateUserProcess
    stealthy remote process injection - chunking
    using debugging & NtQueueApcThread for payload execution

To see this hidden content, you must like this content.
 
Status
Not open for further replies.
Back
Top