Damaged - Embrace the Infinite

Step into the world of endless opportunities and unlock the gateway to virtual transactions.

  • Domain Update: Our Forum has moved! Please visit us at Damaged.gg for the latest updates.

GIT - TerraLdr Payload loader

fightsdntmatter

Premium member
Premium

0

0%

Status

Offline

Posts

20

Likes

0

Rep

0

Bits

0

2

Years of Service

TerraLdr - A Payload Loader Designed With Advanced
Evasion Features

like, comment, stick afinger in ur butt, etc..;

TerraLdr: A Payload Loader Designed With Advanced Evasion FeaturesDetails:
  • no crt functions imported
  • syscall unhooking usingKnownDllUnhook
  • api hashing using Rotr32 hashing algo
  • payload encryption using rc4 - payload is saved in .rsrc
  • process injection - targetting 'SettingSyncHost.exe'
  • ppid spoofing & blockdlls policy using NtCreateUserProcess
  • stealthy remote process injection - chunking
  • using debugging & NtQueueApcThread for payload execution
Usage:
Thanks For:
Profit:[Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png][Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg]



[HIDE] https://github.com/ORC41/TerraLdr
[/HIDE]
Tele: @G0G0Provides
 

alhosane

Member

0

0%

Status

Offline

Posts

26

Likes

0

Rep

0

Bits

0

11

Months of Service

YuuCMYK

Member

0

0%

Status

Offline

Posts

26

Likes

0

Rep

0

Bits

0

2

Years of Service

(31 October, 2022 - 11:00 PM)fightsdntmatter Wrote: Show More
TerraLdr - A Payload Loader Designed With Advanced
Evasion Features

like, comment, stick afinger in ur butt, etc..;

TerraLdr: A Payload Loader Designed With Advanced Evasion FeaturesDetails:
  • no crt functions imported
  • syscall unhooking usingKnownDllUnhook
  • api hashing using Rotr32 hashing algo
  • payload encryption using rc4 - payload is saved in .rsrc
  • process injection - targetting 'SettingSyncHost.exe'
  • ppid spoofing & blockdlls policy using NtCreateUserProcess
  • stealthy remote process injection - chunking
  • using debugging & NtQueueApcThread for payload execution
Usage:
Thanks For:
Profit:[Image: 198824933-101d0641-d8b3-4cef-812d-0834cdb8cf0f.png][Image: 198824884-ba516101-0b02-4ff7-94fb-65ce692e02ce.jpg]

thx
 

48,655

38,233

238,383

Top