DLL Jmping: Old Hollow Trampolines in Windows DLL Land
ID: 4f67ead2-cc9d-5fb4-9ab2-6e9d58cfdba8
STIX ID: report--4f67ead2-cc9d-5fb4-9ab2-6e9d58cfdba8
Feed Name: Black Hills Infosec Blog
Threat Score
This blog details a stealthy Windows payload-delivery technique that dynamically finds non-CFG system DLLs, locates their .text sections, and writes a small mov/call trampoline at each DLL start to build a chained execution path to memory-backed shellcode; the post includes source code, testing artifacts (Process Hacker screenshots), and VirusTotal comparisons showing substantially lower detection for chained samples versus a direct call.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
