malware source code
search
⌘Ctrlk
malware source code
  • message-smileIntroduction
  • Code base
    • file-circle-exclamationHeaders
    • pageCRT Recreation
  • pageString Hashing
  • pageAntidebugging Methods
  • pageLibrary Loading
  • pageError Handling
  • pageFingerprinting
  • pageWrappers and Helpers
  • pageProcess Creation Techniques
  • pageShellcode Execution
  • pageCompression
  • pageNetworking
  • pageLsass Related
  • pageProxied Functions
  • pageEvasion
    • AmsiBypass by Patching (OLD)
    • Delay execution until monitor off
    • Unlink DLL from process
    • Sleep Obfuscation (unstable)
  • pageComponent Object Model
  • My Projects
    • Proof-of-Concepts
    • Write-ups
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

pageEvasion

AmsiBypass by Patching (OLD)chevron-rightDelay execution until monitor offchevron-rightUnlink DLL from processchevron-rightSleep Obfuscation (unstable)chevron-right
PreviousIERemoveDirectorychevron-leftNextAmsiBypass by Patching (OLD)chevron-right