• 📢 Notice: Our community has moved to Zelo.cx! Visit us at Zelo.cx for the latest updates and discussions.

GIT - TerraLdr Payload loader

fightsdntmatter

Premium member
Premium
Rep
0
0
0
Rep
0
Vouches
0
0
0
Vouches
0
Posts
20
Likes
0
Bits
3 YEARS
3 YEARS OF SERVICE
TerraLdr - A Payload Loader Designed With Advanced
Evasion Features

like, comment, stick afinger in ur butt, etc..;

TerraLdr: A Payload Loader Designed With Advanced Evasion FeaturesDetails:
  • no crt functions imported
  • syscall unhooking usingKnownDllUnhook
  • api hashing using Rotr32 hashing algo
  • payload encryption using rc4 - payload is saved in .rsrc
  • process injection - targetting 'SettingSyncHost.exe'
  • ppid spoofing & blockdlls policy using NtCreateUserProcess
  • stealthy remote process injection - chunking
  • using debugging & NtQueueApcThread for payload execution
Usage:
Thanks For:
Profit:[Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png][Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg]



[HIDE] https://github.com/ORC41/TerraLdr
[/HIDE]
Tele: @G0G0Provides
 

alhosane

Member
Rep
0
0
0
Rep
0
Vouches
0
0
0
Vouches
0
Posts
26
Likes
0
Bits
2 YEARS
2 YEARS OF SERVICE

YuuCMYK

Member
Rep
0
0
0
Rep
0
Vouches
0
0
0
Vouches
0
Posts
26
Likes
0
Bits
3 YEARS
3 YEARS OF SERVICE
(31 October, 2022 - 11:00 PM)fightsdntmatter Wrote: Show More
TerraLdr - A Payload Loader Designed With Advanced
Evasion Features

like, comment, stick afinger in ur butt, etc..;

TerraLdr: A Payload Loader Designed With Advanced Evasion FeaturesDetails:
  • no crt functions imported
  • syscall unhooking usingKnownDllUnhook
  • api hashing using Rotr32 hashing algo
  • payload encryption using rc4 - payload is saved in .rsrc
  • process injection - targetting 'SettingSyncHost.exe'
  • ppid spoofing & blockdlls policy using NtCreateUserProcess
  • stealthy remote process injection - chunking
  • using debugging & NtQueueApcThread for payload execution
Usage:
Thanks For:
Profit:[Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png][Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg]

thx
 

48,736

38,247

238,888

Top