logo

DLL Jmping: Old Hollow Trampolines in Windows DLL Land

ID: 4f67ead2-cc9d-5fb4-9ab2-6e9d58cfdba8

STIX ID: report--4f67ead2-cc9d-5fb4-9ab2-6e9d58cfdba8

Feed Name: Black Hills Infosec Blog

Threat Score
72/100

Date Published: 2024-06-06

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog details a stealthy Windows payload-delivery technique that dynamically finds non-CFG system DLLs, locates their .text sections, and writes a small mov/call trampoline at each DLL start to build a chained execution path to memory-backed shellcode; the post includes source code, testing artifacts (Process Hacker screenshots), and VirusTotal comparisons showing substantially lower detection for chained samples versus a direct call.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.