Executing shellcode in memory | Malware Development

แชร์
ฝัง
  • เผยแพร่เมื่อ 4 ก.พ. 2025

ความคิดเห็น • 32

  • @danielrodriguez5960
    @danielrodriguez5960 10 หลายเดือนก่อน +1

    screeck: "I was a fool that night" LOL

  • @kamalchan9756
    @kamalchan9756 4 หลายเดือนก่อน +1

    you should xor windows apis

  • @sul3y
    @sul3y ปีที่แล้ว +2

    The detection isn’t because of the encrypted Shellcode itself rather it was the use of AES encryption most of AVs signature these as malicious cause who would encrypt some BYTEs and call VirtualAlloc, CreateThread functions other than hackers

  • @C5pider
    @C5pider ปีที่แล้ว +5

    cool video. just be aware that you have to handle the errors returned by win32 apis (VirtualAlloc, CreateThread, etc.). It is good progamming pratice to do so :P and you will figure out faster on why something doesnt work.

    • @screeck
      @screeck  ปีที่แล้ว +1

      Good point, I forgot about it. And thanks :)

    • @UnhandledErrorWasTaken
      @UnhandledErrorWasTaken ปีที่แล้ว

      yooo spider from maldev accademyyy

  • @Dzikk
    @Dzikk ปีที่แล้ว

    Siemson, masz dc do siebie?

  • @novianindy887
    @novianindy887 ปีที่แล้ว +1

    is it detected by most AV now? Do you use any NTDLL.dll and is it not hooked by the AV ?

  • @jamiedbighill7792
    @jamiedbighill7792 ปีที่แล้ว

    u are seriously skilled

    • @screeck
      @screeck  ปีที่แล้ว +1

      Thanks, but I'm still a beginner, there is a long way ahead of me to master this things

    • @jamiedbighill7792
      @jamiedbighill7792 ปีที่แล้ว

      @@screeck same

  • @chathurangaonnet
    @chathurangaonnet 10 หลายเดือนก่อน +1

    Thanks for the effort !!!

  • @exe.m1dn1ght
    @exe.m1dn1ght หลายเดือนก่อน

    hi screeck, why you dont post anymore ?

    • @screeck
      @screeck  หลายเดือนก่อน +1

      No time. But I'll be back, I'm not giving up on this channel for sure.I also dont wanna make low quality content so I would rather wait for a good moment to start posting videos again thatn post random stuff now.

  • @aliena7407
    @aliena7407 ปีที่แล้ว

    bro please post more vids about malware development thank you!

    • @screeck
      @screeck  ปีที่แล้ว +1

      Thanks, there will be a lot more but in february, I have tons of exams at uni right now 😂

    • @aliena7407
      @aliena7407 ปีที่แล้ว

      @@screeck okay bro goodluck

  • @AidenPearce-i6d
    @AidenPearce-i6d 11 หลายเดือนก่อน

    do the full course for maldev

  • @koshane522
    @koshane522 ปีที่แล้ว

    Could you please tell me how can i learn about win32 api to write well?

    • @screeck
      @screeck  ปีที่แล้ว +4

      I'm no professional so I can't tell you what to do step-by-step.
      My way of learning things is to do it "on the fly".
      Think about something cool that you whould like to build (something that will use win32 api), and start researching.
      Google, "how to do X using win32api" or something simmilar.
      Learning by doing projects is never boring and very rewarding
      Also Microsoft's documentation will always be your best friend (link in the description).
      Good luck!

  • @DutchNorthAtlanticAlliance
    @DutchNorthAtlanticAlliance 4 หลายเดือนก่อน

    Bro, can you cover Windows Registry hacking BRO

  • @MalwareHunter_07
    @MalwareHunter_07 9 หลายเดือนก่อน

    And bro plz try and test your payloads on EDR as well :)

  • @TechnologicAll
    @TechnologicAll 6 หลายเดือนก่อน

    nice, but virustotal redistribute the results

  • @aliena7407
    @aliena7407 ปีที่แล้ว

    thanks for info!

  • @VenziL
    @VenziL ปีที่แล้ว

    Well, no matter how much everyone asks not to upload to virustotal, they still upload it... why!?

    • @screeck
      @screeck  ปีที่แล้ว

      Hah, after this I won't upload my binaries to VT anymore, but I still need a place to test them tho. You know any good alternatives?

    • @VenziL
      @VenziL 10 หลายเดือนก่อน

      ​@@screeckI would advise you to find out how to create sandboxes to test such files. In fact, the “Virus Total” is the same sandbox with antiviruses that sends reports about each file to the company. Of course, there are other services that may be analogues of this and “not send reports”, but I personally trust only what I can create myself.

    • @VenziL
      @VenziL 10 หลายเดือนก่อน

      ​@@screeckI would suggest you learn how to create sandboxes to test such files. Essentially, “VT” is the same sandbox with antiviruses that sends reports to companies about each file.

    • @VenziL
      @VenziL 10 หลายเดือนก่อน

      I would suggest you learn how to create sandboxes to test such files. Essentially, “VT” is the same sandbox that sends reports to companies about each file.

    • @MalwareHunter_07
      @MalwareHunter_07 9 หลายเดือนก่อน

      @@screeck use Cuckoo Sandbox

  • @stanislavsmetanin1307
    @stanislavsmetanin1307 4 หลายเดือนก่อน

    Never upload to virustotal. It will be worked through and day later your work is scratched