Skip to content
Ege Balcı edited this page Dec 16, 2018 · 9 revisions
  • Add process hollowing stub
  • Remove all external dependencies
  • Add resource loading method for payloads
  • Add.NET file support
  • Write a unpacker for Amber payloads
  • Add x64 support
  • Add DLL support
  • Add PE header scraper to map function
  • Add a IAT parser shellcode to stub
  • Add yara rules to repo
  • Add RC4 encryption to payloads
Clone this wiki locally