Xed Injector - Manual Map/LdrLoadDllStub/Thread Hijacking/Cloaking

Posts 1–9 of 9 · Page 1 of 1
Xed Injector - Manual Map/LdrLoadDllStub/Thread Hijacking/Cloaking
Xed Injector

An advanced injector with fresh code in order to be sure there will be no interruptions while attempting to use your cheat.

Screenshots:



Injection methods:
- Load Library (Simple, safe injection, but detected)
- Manual Map (Not simple manual map, but instead it maps an actual loader for your image, making sure it will stay undetected)
- LdrLoadDllStub (One level deeper into LoadLibrary, this is a re-written version of the exported function LdrLoadDllStub)
- Thread Hijacking (This is completely undetected for the moment and can be used in a vast majority of applications)

Other options:
- Spoof PE Header (Replaces your image's PE header with one from the kernel32 module, thus reducing detection rates)
- Cloak module (Makes your image invisible in the module list)

Upcoming:
In the case that this release won't be a complete failure, I have the following features in my head for the next version:
- I will make this ugly GUI into a more compact and easy to use one
- Make the process list easier to navigate (and maybe include the icons)
- Add double thread hijacking and LdrpLoadDllStub
- Include console versions so you can use them instead or use them with your own programs
- Automatic x64 architecture process detection (didn't have time to include it in this version, was in a bit of a hurry)
- View what caused the error

Scans:
These files are virtualized with VMProtect, thus the detection rates will probably be a bit high. Also, cannot post VT scan because it is currently broken.
https://virusscan.jotti.org/en-US/fi...job/0tjmgtoe5gⓘ
https://metadefender.com/#!/results/...gular/analysisⓘ

If you have any issues with this or any other questions in general, feel free to ask. Also, if the GUI is broken in any way, post it here and I'll fix it asap. I haven't really payed much attention to it, it's just a very simple VB code. Will probably switch to something like Delphi or just use MFC for the GUI later on.
Xed Injector_mpgh.net.rar1.3 MB · 2,038 downloads 3/61 malicious
Quote Originally Posted by Ahl View Post
@capital008 2 screenshots and 2 virus scans are required
Added. Maybe you could edit them so the screenshots are view-able and the scans are clickable.
Approved.

This has not been tested
Virüs!!!!!!!!!
Quote Originally Posted by yasiNNN60 View Post
Virüs!!!!!!!!!
Kek. Sure it is a virus.
LoadLib isnt detected. Im using loadlib for months
Sooo did you code the injector or just the gui? Also, having virus scans of the .net file that contains the real commandline injector in its resources (=base64 string) feels a little weird. I extracted the 64 bit version and uploaded to virustotal (remove the space in the url): virustotal.com/#/file/0f957c29e66e9cde8b6b3bcdfa3e5044a38e8f3767a03b9e1b 2fa65c40927430/detection



(I'm not saying this is a virus, I looked at the actual injector and it actually seems clean - not 100% sure though)
Posts 1–9 of 9 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?