research-virus / net-traveler
Public open-source code of malware NetTraveler (aka TravNet).
☆36Updated 9 years ago
Alternatives and similar repositories for net-traveler:
Users that are interested in net-traveler are comparing it to the libraries listed below
- Public open-source code of malware Shamoon (aka Disttrack).☆35Updated 9 years ago
- GreenKit is an userland rootkit hiding its own files and mining bitcoins on compromised computers. Do /NOT/ download or use this rootkit …☆42Updated 7 years ago
- Various Crypter Project☆51Updated 10 years ago
- Protects deletion of files with a specified extension using a kernel-mode driver.☆75Updated 6 years ago
- Gozi-MBR-rootkit Bootkit Modified☆68Updated 8 years ago
- A Win32 PE/Executable Crypter that employs on the fly encryption & decryption of memory☆33Updated 11 years ago
- Infects PE files with a shellcode☆17Updated 6 years ago
- Parser for a custom executable format from Hidden Bee malware (first stage)☆39Updated 5 months ago
- Class implementation of PowerLoader injection technique☆29Updated 8 years ago
- A simple rootkit to hide a process☆46Updated 11 years ago
- A ready-made template for a project based on libpeconv.☆44Updated 4 months ago
- Project aimed at creating a malware able to evolve and adapt to the various host machines through metamorphic modifications, spontaneous …☆41Updated 7 years ago
- Simple PE packer with RtlCompressBuffer☆21Updated 9 years ago
- The Grum Spam Bot☆20Updated 9 years ago
- ☆12Updated 7 years ago
- An example of PE hollowing injection technique☆22Updated 5 years ago
- Sysprep Volatile Environment LPE (2017)☆14Updated 2 months ago
- TaskMgr Volatile Environment LPE☆13Updated 2 months ago
- A Proof-of-Concept win32 DLL that makes use of netbios session token replay to propagate through a Windows Domain☆25Updated 6 years ago
- PoC for detecting and dumping code injection (built and extended on UnRunPE)☆56Updated 6 years ago
- Decrement Windows Kernel for fun and profit☆37Updated 7 years ago
- DirectNtApi - simple method to make ntapi function call without importing or walking export table. Work under Windows 7, 8 and 10☆52Updated 11 months ago
- User-mode process cross-checking utility intended to detect naive malware hiding itself by hooking IAT/EAT.☆19Updated 8 years ago
- Simple C++ ransomware, prove the concept.☆25Updated 7 years ago
- PoC designed to evade userland-hooking anti-virus.☆88Updated 5 years ago
- Enter Product Key Volatile Environment LPE☆12Updated 2 months ago
- Simple tool for unpacking packed/protected malware executables.☆32Updated 13 years ago
- Minimal Intervention and Software Transformation - PoC Packer designed for AV detection bypass☆18Updated 7 years ago
- r0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems☆10Updated 6 years ago
- Bypass antivirus with dynamic import. Hide the api(s) used.☆26Updated 8 years ago