Vasco0x4 / ShadeLoader

ShadeLoader is a shellcode loader designed to bypass most antivirus software. 壳代码, 杀毒软件, 绕过
36 stars 4 forks source link

Shellcode from EXE #5

Open Vittix07 opened 1 month ago

Vittix07 commented 1 month ago

Can I use the shellcode of an exe file?

Vittix07 commented 1 month ago

Like taking the shellcode from an executable file of my choice?

Vasco0x4 commented 1 month ago

That's an interesting question In theory, it should work, but it depends on the executable you want to use. Because the loader injects the binary into another process.

Let us know the results :))

Vittix07 commented 1 month ago

Could you advise me the best way to acquire the shellcode of an executable file? Sorry, I'm not very practical 😅

Vittix07 commented 1 month ago

And then one last question, is this an alternative hollowing process not detected yet right? If so, what are the differences between this and classic process hollowing, what makes it undetected?