malware source code
⌘Ctrlk
malware source code
  • Introduction
  • Headers
  • CRT Recreation
  • String Hashing
  • Antidebugging Methods
  • Library Loading
  • Error Handling
  • Fingerprinting
  • Wrappers and Helpers
  • Process Creation Techniques
  • Shellcode Execution
  • Compression
  • Networking
  • Lsass Related
  • Proxied Functions
  • Evasion
    • AmsiBypass by Patching (OLD)
    • Delay execution until monitor off
    • Unlink DLL from process
    • Sleep Obfuscation (unstable)
  • Component Object Model
    • Proof-of-Concepts
    • Write-ups
    • Malware reversing (shorts)
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.

Evasion

AmsiBypass by Patching (OLD)Delay execution until monitor offUnlink DLL from processSleep Obfuscation (unstable)
PreviousIERemoveDirectoryNextAmsiBypass by Patching (OLD)