/PEx64-Injector

A tool for injecting 64-bit executables into legitimate processes. Users can specify a local file or download one from a URL, with all operations performed in memory to evade antivirus detection.

Primary LanguageC#

PEx64-Injector (Process Migrator)

Migrate any x64 exe to any x64 process (Net FrameWork 3.5)

No Administrator privileges required.

GIF Demo

PoC

How can be used?

shot

Download here.

Usage: Migrator.exe payload(fpath) Migratefile(fpath)

Example: Migrator.exe C:\Users\User\Desktop\Putty64.exe C:\Windows\System32\notepad.exe

Keep as a note that when you specify the migratefile it will launch as a new process and won't migrate to an already running process.

Such tool can be utilized for AV evasion, masking malicious software under legitimate process.

Code

Todo: download/execute function to load remote files.
Special thanks to GigaJew.