malware source code
search
⌘Ctrlk
malware source code
  • message-smileIntroduction
  • Code base
    • file-circle-exclamationHeaders
    • pageCRT Recreation
  • pageString Hashing
  • pageAntidebugging Methods
  • pageLibrary Loading
  • pageError Handling
  • pageFingerprinting
  • pageWrappers and Helpers
  • pageProcess Creation Techniques
    • WindowsRHotKey
    • WindowsRHotKeyEx
    • IeFrameOpenUrl
    • INFSectionInstallString
    • INFSectionInstallString2
    • INFSetupCommand
    • CreateProcessFromMsHTML
    • CreateProcessFromPcwUtilW
    • ShdocVwOpenUrl
    • ShellExecRunDLL
    • UrlFileProtocolHandler
    • CoShellExecute
    • UrlOpenUrl
    • ZipfldrRouteCall
    • NtCreateUserProcess
    • CreateProcessWithCfGuard
    • CoShellWindowExecute
    • RunAsNewUserDllW
    • IHxHelpPaneServer
    • WmiWin32_CreateProcess
    • IHxInteractiveUser
    • Touch Injection Click on Desktop Binary
  • pageShellcode Execution
  • pageCompression
  • pageNetworking
  • pageLsass Related
  • pageProxied Functions
  • pageEvasion
  • pageComponent Object Model
  • My Projects
    • Proof-of-Concepts
    • Write-ups
gitbookPowered by GitBook
block-quoteOn this pagechevron-down

pageProcess Creation Techniques

WindowsRHotKeychevron-rightWindowsRHotKeyExchevron-rightIeFrameOpenUrlchevron-rightINFSectionInstallStringchevron-rightINFSectionInstallString2chevron-rightINFSetupCommandchevron-rightCreateProcessFromMsHTMLchevron-rightCreateProcessFromPcwUtilWchevron-rightShdocVwOpenUrlchevron-rightShellExecRunDLLchevron-rightUrlFileProtocolHandlerchevron-rightCoShellExecutechevron-rightUrlOpenUrlchevron-rightZipfldrRouteCallchevron-rightNtCreateUserProcesschevron-rightCreateProcessWithCfGuardchevron-rightCoShellWindowExecutechevron-rightRunAsNewUserDllWchevron-rightIHxHelpPaneServerchevron-rightWmiWin32_CreateProcesschevron-rightIHxInteractiveUserchevron-rightTouch Injection Click on Desktop Binarychevron-right
PreviousMasquerade Peb as Explorerchevron-leftNextWindowsRHotKeychevron-right