内容仅以原始语言提供
class="post-article">

ReflectiveDLLInjector

Reflective DLL injector targeting svchost.exe. Internal name SvchostInjector.x64.dll. ReflectiveLoader fileless injection. Direct NTDLL syscall access for ETW/AV bypass. Process enumeration via CreateToolhelp32Snapshot. Memory-mapped injection. 128-char AES key config string.

威胁档案
类型 Loader
编程语言C/C++
C2协议Named Pipe/C2
首次发现2024
目标 Küresel
用途 / 能力
  • Process Injection/Fileless Loader
尚未发现该家族的 C2 服务器。

研究报告 (1)

Kritik

ReflectiveDLLInjector out.dll -- SvchostInjector.x64.dll Dahili Isim, ReflectiveLoader Dosyasiz Enjeksiyon, ntdll.dll Direkt Syscall ETW AV Bypass, CreateToolhelp32Snapshot Process32FirstW Hedef Proses Tespiti | Kritik

ReflectiveDLLInjector out.dll x64. SvchostInjector.x64.dll dahili isim. ReflectiveLoader dosyasiz enjeksiyon. ntdll.dll direkt syscall ETW AV bypass. CreateToolhelp32Snapshot Process32FirstW hedef proses tespiti.

阅读报告 →