fightsdntmatter
Premium member
Premium
- Thread Author
- #2
TerraLdr - A Payload Loader Designed With Advanced
Evasion Features
like, comment, stick afinger in ur butt, etc..;
TerraLdr: A Payload Loader Designed With Advanced Evasion FeaturesDetails:
Profit:![[Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png] [Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fuser-images.githubusercontent.com%2F111295429%2F198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png)
![[Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg] [Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fuser-images.githubusercontent.com%2F111295429%2F198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg)
[HIDE] https://github.com/ORC41/TerraLdr
[/HIDE]
Tele: @G0G0Provides
Evasion Features
like, comment, stick afinger in ur butt, etc..;
TerraLdr: A Payload Loader Designed With Advanced Evasion FeaturesDetails:
- no crt functions imported
- syscall unhooking usingKnownDllUnhook
- api hashing using Rotr32 hashing algo
- payload encryption using rc4 - payload is saved in .rsrc
- process injection - targetting 'SettingSyncHost.exe'
- ppid spoofing & blockdlls policy using NtCreateUserProcess
- stealthy remote process injection - chunking
- using debugging & NtQueueApcThread for payload execution
- useGenerateRsrcto updateDataFile.terrathat'll be the payload saved in the .rsrc section of the loader
Profit:
![[Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png] [Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fuser-images.githubusercontent.com%2F111295429%2F198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png)
![[Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg] [Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg]](https://external-content.duckduckgo.com/iu/?u=https%3A%2F%2Fuser-images.githubusercontent.com%2F111295429%2F198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg)
[HIDE] https://github.com/ORC41/TerraLdr
[/HIDE]
Tele: @G0G0Provides