malware source code
⌘Ctrlk
malware source code
  • Introduction
  • Headers
  • CRT Recreation
  • String Hashing
  • Antidebugging Methods
  • Library Loading
  • Error Handling
  • Fingerprinting
  • Wrappers and Helpers
  • Process Creation Techniques
  • Shellcode Execution
  • Compression
  • Networking
  • Lsass Related
  • Proxied Functions
  • Evasion
  • Component Object Model
    • Proof-of-Concepts
      • "Jeff", COM-only keylogger
      • "Russian Doll", Recursive file loader
      • "Branchy", Branchless keylogger
      • "Fever Dream" - Code executing when the Windows machine is locked
      • Creating "Ransomware" Using WinRT
      • Getting Clipboard History in C++
      • Hiding data in GPU VRAM using Direct3D 11
      • OCRMe, dumping OneDrive Business OCR Data
      • Meow Meow Kitty Cat Meow Meow
      • No Need COM WMI
      • Disabling Bitlocker Encryption using undocumented COM objects
      • Stupid callbacks for malware evasion
      • Microsoft Copilot, Copilot my payload
      • HTTPS TLS with AFD.sys, WinSocks not necessary
      • NoNamed Mutation Engine
    • Write-ups
    • Malware reversing (shorts)
Powered by GitBook
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. My Projects

Proof-of-Concepts

"Jeff", COM-only keylogger"Russian Doll", Recursive file loader"Branchy", Branchless keylogger"Fever Dream" - Code executing when the Windows machine is lockedCreating "Ransomware" Using WinRTGetting Clipboard History in C++Hiding data in GPU VRAM using Direct3D 11OCRMe, dumping OneDrive Business OCR DataMeow Meow Kitty Cat Meow MeowNo Need COM WMIDisabling Bitlocker Encryption using undocumented COM objectsStupid callbacks for malware evasionMicrosoft Copilot, Copilot my payloadHTTPS TLS with AFD.sys, WinSocks not necessaryNoNamed Mutation Engine
PreviousCoEnumUPnPDevicesNext"Jeff", COM-only keylogger