mirror of
https://github.com/Astharot15/COMLoaderAstharot/
synced 2026-07-13 20:52:26 +00:00
Update README with technical details
Added details about hijack targets, callback, download function, payload synchronization, and COM object reliability.
This commit is contained in:
@@ -3,7 +3,11 @@
|
|||||||
### Interesting details
|
### Interesting details
|
||||||
|
|
||||||
The hijack targets chrome and msedge; it also works in explorer, but it is likely to crash.
|
The hijack targets chrome and msedge; it also works in explorer, but it is likely to crash.
|
||||||
|
|
||||||
The callback used is **LdrCallEnclave**.
|
The callback used is **LdrCallEnclave**.
|
||||||
|
|
||||||
A Download function is commented out. It worked in the .exe compilation, but when compiled as a dll, it gets caught by AVs; so instead of using wininet, winhttp was used.
|
A Download function is commented out. It worked in the .exe compilation, but when compiled as a dll, it gets caught by AVs; so instead of using wininet, winhttp was used.
|
||||||
|
|
||||||
The payload uses event objects for process synchronization rather than a traditional mutex.
|
The payload uses event objects for process synchronization rather than a traditional mutex.
|
||||||
|
|
||||||
The COM object is very reliable; it has been working for 6 months without crashes.
|
The COM object is very reliable; it has been working for 6 months without crashes.
|
||||||
|
|||||||
Reference in New Issue
Block a user